volatility3.plugins.windows.malware package
All core windows malware plugins.
These modules should only be imported from volatility3.plugins NOT volatility3.framework.plugins
Submodules
- volatility3.plugins.windows.malware.direct_system_calls module
DirectSystemCallsDirectSystemCalls.build_configuration()DirectSystemCalls.configDirectSystemCalls.config_pathDirectSystemCalls.contextDirectSystemCalls.get_disasm_function()DirectSystemCalls.get_range_path()DirectSystemCalls.get_requirements()DirectSystemCalls.get_tasks_to_scan()DirectSystemCalls.get_vad_maps()DirectSystemCalls.make_subconfig()DirectSystemCalls.openDirectSystemCalls.run()DirectSystemCalls.set_open_method()DirectSystemCalls.unsatisfied()DirectSystemCalls.valid_syscall_handlersDirectSystemCalls.version
syscall_finder_type
- volatility3.plugins.windows.malware.drivermodule module
- volatility3.plugins.windows.malware.hollowprocesses module
DLLDataHollowProcessesHollowProcesses.build_configuration()HollowProcesses.configHollowProcesses.config_pathHollowProcesses.contextHollowProcesses.get_requirements()HollowProcesses.make_subconfig()HollowProcesses.openHollowProcesses.run()HollowProcesses.set_open_method()HollowProcesses.unsatisfied()HollowProcesses.version
VadData
- volatility3.plugins.windows.malware.indirect_system_calls module
IndirectSystemCallsIndirectSystemCalls.build_configuration()IndirectSystemCalls.configIndirectSystemCalls.config_pathIndirectSystemCalls.contextIndirectSystemCalls.get_disasm_function()IndirectSystemCalls.get_range_path()IndirectSystemCalls.get_requirements()IndirectSystemCalls.get_tasks_to_scan()IndirectSystemCalls.get_vad_maps()IndirectSystemCalls.make_subconfig()IndirectSystemCalls.openIndirectSystemCalls.run()IndirectSystemCalls.set_open_method()IndirectSystemCalls.unsatisfied()IndirectSystemCalls.valid_syscall_handlersIndirectSystemCalls.version
- volatility3.plugins.windows.malware.ldrmodules module
- volatility3.plugins.windows.malware.malfind module
MalfindMalfind.build_configuration()Malfind.configMalfind.config_pathMalfind.contextMalfind.get_requirements()Malfind.is_vad_empty()Malfind.list_injection_sites()Malfind.list_injections()Malfind.make_subconfig()Malfind.openMalfind.run()Malfind.set_open_method()Malfind.unsatisfied()Malfind.version
- volatility3.plugins.windows.malware.pebmasquerade module
PebMasqueradePebMasquerade.build_configuration()PebMasquerade.configPebMasquerade.config_pathPebMasquerade.contextPebMasquerade.get_process_names()PebMasquerade.get_requirements()PebMasquerade.make_subconfig()PebMasquerade.openPebMasquerade.run()PebMasquerade.set_open_method()PebMasquerade.unsatisfied()PebMasquerade.version
- volatility3.plugins.windows.malware.processghosting module
ProcessGhostingProcessGhosting.build_configuration()ProcessGhosting.check_for_ghosting()ProcessGhosting.configProcessGhosting.config_pathProcessGhosting.contextProcessGhosting.get_requirements()ProcessGhosting.make_subconfig()ProcessGhosting.openProcessGhosting.run()ProcessGhosting.set_open_method()ProcessGhosting.unsatisfied()ProcessGhosting.version
- volatility3.plugins.windows.malware.psxview module
- volatility3.plugins.windows.malware.skeleton_key_check module
Skeleton_Key_CheckSkeleton_Key_Check.build_configuration()Skeleton_Key_Check.configSkeleton_Key_Check.config_pathSkeleton_Key_Check.contextSkeleton_Key_Check.get_requirements()Skeleton_Key_Check.make_subconfig()Skeleton_Key_Check.openSkeleton_Key_Check.run()Skeleton_Key_Check.set_open_method()Skeleton_Key_Check.unsatisfied()Skeleton_Key_Check.version
- volatility3.plugins.windows.malware.suspicious_threads module
SuspiciousThreadsSuspiciousThreads.build_configuration()SuspiciousThreads.configSuspiciousThreads.config_pathSuspiciousThreads.contextSuspiciousThreads.get_requirements()SuspiciousThreads.make_subconfig()SuspiciousThreads.openSuspiciousThreads.run()SuspiciousThreads.set_open_method()SuspiciousThreads.unsatisfied()SuspiciousThreads.version
- volatility3.plugins.windows.malware.svcdiff module
SvcDiffSvcDiff.build_configuration()SvcDiff.configSvcDiff.config_pathSvcDiff.contextSvcDiff.enumerate_vista_or_later_header()SvcDiff.get_prereq_info()SvcDiff.get_record_tuple()SvcDiff.get_requirements()SvcDiff.make_subconfig()SvcDiff.openSvcDiff.run()SvcDiff.service_diff()SvcDiff.service_scan()SvcDiff.set_open_method()SvcDiff.unsatisfied()SvcDiff.version
- volatility3.plugins.windows.malware.unhooked_system_calls module
UnhookedSystemCallsUnhookedSystemCalls.build_configuration()UnhookedSystemCalls.configUnhookedSystemCalls.config_pathUnhookedSystemCalls.contextUnhookedSystemCalls.get_requirements()UnhookedSystemCalls.make_subconfig()UnhookedSystemCalls.openUnhookedSystemCalls.run()UnhookedSystemCalls.set_open_method()UnhookedSystemCalls.system_callsUnhookedSystemCalls.unsatisfied()UnhookedSystemCalls.version