volatility3.plugins.windows package
All Windows OS plugins.
NOTE: This file is important for core plugins to run (which certain components such as the windows registry layers) are dependent upon, please DO NOT alter or remove this file unless you know the consequences of doing so.
The framework is configured this way to allow plugin developers/users to override any plugin functionality whether existing or new.
When overriding the plugins directory, you must include a file like this in any subdirectories that may be necessary.
Subpackages
Submodules
- volatility3.plugins.windows.bigpools module
- volatility3.plugins.windows.cachedump module
CachedumpCachedump.build_configuration()Cachedump.configCachedump.config_pathCachedump.contextCachedump.decrypt_hash()Cachedump.get_nlkm()Cachedump.get_requirements()Cachedump.make_subconfig()Cachedump.openCachedump.parse_cache_entry()Cachedump.parse_decrypted_cache()Cachedump.run()Cachedump.set_open_method()Cachedump.unsatisfied()Cachedump.version
- volatility3.plugins.windows.callbacks module
CallbacksCallbacks.build_configuration()Callbacks.configCallbacks.config_pathCallbacks.contextCallbacks.create_callback_table()Callbacks.get_requirements()Callbacks.list_bugcheck_callbacks()Callbacks.list_bugcheck_reason_callbacks()Callbacks.list_notify_routines()Callbacks.list_registry_callbacks()Callbacks.make_subconfig()Callbacks.openCallbacks.run()Callbacks.set_open_method()Callbacks.unsatisfied()Callbacks.version
- volatility3.plugins.windows.cmdline module
- volatility3.plugins.windows.crashinfo module
- volatility3.plugins.windows.devicetree module
- volatility3.plugins.windows.dlllist module
- volatility3.plugins.windows.driverirp module
- volatility3.plugins.windows.drivermodule module
- volatility3.plugins.windows.driverscan module
DriverScanDriverScan.build_configuration()DriverScan.configDriverScan.config_pathDriverScan.contextDriverScan.get_names_for_driver()DriverScan.get_requirements()DriverScan.make_subconfig()DriverScan.openDriverScan.run()DriverScan.scan_drivers()DriverScan.set_open_method()DriverScan.unsatisfied()DriverScan.version
- volatility3.plugins.windows.dumpfiles module
DumpFilesDumpFiles.build_configuration()DumpFiles.configDumpFiles.config_pathDumpFiles.contextDumpFiles.dump_file_producer()DumpFiles.get_requirements()DumpFiles.make_subconfig()DumpFiles.openDumpFiles.process_file_object()DumpFiles.run()DumpFiles.set_open_method()DumpFiles.unsatisfied()DumpFiles.version
- volatility3.plugins.windows.envars module
- volatility3.plugins.windows.filescan module
- volatility3.plugins.windows.getservicesids module
GetServiceSIDsGetServiceSIDs.build_configuration()GetServiceSIDs.configGetServiceSIDs.config_pathGetServiceSIDs.contextGetServiceSIDs.get_requirements()GetServiceSIDs.make_subconfig()GetServiceSIDs.openGetServiceSIDs.run()GetServiceSIDs.set_open_method()GetServiceSIDs.unsatisfied()GetServiceSIDs.version
createservicesid()
- volatility3.plugins.windows.getsids module
- volatility3.plugins.windows.handles module
HandlesHandles.build_configuration()Handles.configHandles.config_pathHandles.contextHandles.find_cookie()Handles.find_sar_value()Handles.get_requirements()Handles.get_type_map()Handles.handles()Handles.make_subconfig()Handles.openHandles.run()Handles.set_open_method()Handles.unsatisfied()Handles.version
- volatility3.plugins.windows.hashdump module
HashdumpHashdump.almpasswordHashdump.antpasswordHashdump.anumHashdump.aqwertyHashdump.bootkey_perm_tableHashdump.build_configuration()Hashdump.configHashdump.config_pathHashdump.contextHashdump.decrypt_single_hash()Hashdump.decrypt_single_salted_hash()Hashdump.empty_lmHashdump.empty_ntHashdump.get_bootkey()Hashdump.get_hbootkey()Hashdump.get_hive_key()Hashdump.get_requirements()Hashdump.get_user_hashes()Hashdump.get_user_keys()Hashdump.get_user_name()Hashdump.lmkeyHashdump.make_subconfig()Hashdump.odd_parityHashdump.openHashdump.run()Hashdump.set_open_method()Hashdump.sid_to_key()Hashdump.sidbytes_to_key()Hashdump.unsatisfied()Hashdump.version
- volatility3.plugins.windows.info module
InfoInfo.build_configuration()Info.configInfo.config_pathInfo.contextInfo.get_depends()Info.get_kdbg_structure()Info.get_kernel_module()Info.get_kuser_structure()Info.get_ntheader_structure()Info.get_requirements()Info.get_version_structure()Info.make_subconfig()Info.openInfo.run()Info.set_open_method()Info.unsatisfied()Info.version
- volatility3.plugins.windows.joblinks module
- volatility3.plugins.windows.ldrmodules module
- volatility3.plugins.windows.lsadump module
LsadumpLsadump.build_configuration()Lsadump.configLsadump.config_pathLsadump.contextLsadump.decrypt_aes()Lsadump.decrypt_secret()Lsadump.get_lsa_key()Lsadump.get_requirements()Lsadump.get_secret_by_name()Lsadump.make_subconfig()Lsadump.openLsadump.run()Lsadump.set_open_method()Lsadump.unsatisfied()Lsadump.version
- volatility3.plugins.windows.malfind module
- volatility3.plugins.windows.mbrscan module
- volatility3.plugins.windows.memmap module
- volatility3.plugins.windows.mftscan module
- volatility3.plugins.windows.modscan module
ModScanModScan.build_configuration()ModScan.configModScan.config_pathModScan.contextModScan.find_session_layer()ModScan.get_requirements()ModScan.get_session_layers()ModScan.make_subconfig()ModScan.openModScan.run()ModScan.scan_modules()ModScan.set_open_method()ModScan.unsatisfied()ModScan.version
- volatility3.plugins.windows.modules module
ModulesModules.build_configuration()Modules.configModules.config_pathModules.contextModules.find_session_layer()Modules.get_requirements()Modules.get_session_layers()Modules.list_modules()Modules.make_subconfig()Modules.openModules.run()Modules.set_open_method()Modules.unsatisfied()Modules.version
- volatility3.plugins.windows.mutantscan module
- volatility3.plugins.windows.netscan module
NetScanNetScan.build_configuration()NetScan.configNetScan.config_pathNetScan.contextNetScan.create_netscan_constraints()NetScan.create_netscan_symbol_table()NetScan.determine_tcpip_version()NetScan.generate_timeline()NetScan.get_requirements()NetScan.make_subconfig()NetScan.openNetScan.run()NetScan.scan()NetScan.set_open_method()NetScan.unsatisfied()NetScan.version
- volatility3.plugins.windows.netstat module
NetStatNetStat.build_configuration()NetStat.configNetStat.config_pathNetStat.contextNetStat.create_tcpip_symbol_table()NetStat.enumerate_structures_by_port()NetStat.find_port_pools()NetStat.generate_timeline()NetStat.get_requirements()NetStat.get_tcpip_module()NetStat.list_sockets()NetStat.make_subconfig()NetStat.openNetStat.parse_bitmap()NetStat.parse_hashtable()NetStat.parse_partitions()NetStat.read_pointer()NetStat.run()NetStat.set_open_method()NetStat.unsatisfied()NetStat.version
- volatility3.plugins.windows.poolscanner module
PoolConstraintPoolHeaderScannerPoolScannerPoolScanner.build_configuration()PoolScanner.builtin_constraints()PoolScanner.configPoolScanner.config_pathPoolScanner.contextPoolScanner.generate_pool_scan()PoolScanner.get_pool_header_table()PoolScanner.get_requirements()PoolScanner.make_subconfig()PoolScanner.openPoolScanner.pool_scan()PoolScanner.run()PoolScanner.set_open_method()PoolScanner.unsatisfied()PoolScanner.version
PoolType
- volatility3.plugins.windows.privileges module
- volatility3.plugins.windows.pslist module
PsListPsList.PHYSICAL_DEFAULTPsList.build_configuration()PsList.configPsList.config_pathPsList.contextPsList.create_name_filter()PsList.create_pid_filter()PsList.generate_timeline()PsList.get_requirements()PsList.list_processes()PsList.make_subconfig()PsList.openPsList.process_dump()PsList.run()PsList.set_open_method()PsList.unsatisfied()PsList.version
- volatility3.plugins.windows.psscan module
PsScanPsScan.build_configuration()PsScan.configPsScan.config_pathPsScan.contextPsScan.generate_timeline()PsScan.get_osversion()PsScan.get_requirements()PsScan.make_subconfig()PsScan.openPsScan.run()PsScan.scan_processes()PsScan.set_open_method()PsScan.unsatisfied()PsScan.versionPsScan.virtual_process_from_physical()
- volatility3.plugins.windows.pstree module
- volatility3.plugins.windows.sessions module
- volatility3.plugins.windows.skeleton_key_check module
Skeleton_Key_CheckSkeleton_Key_Check.build_configuration()Skeleton_Key_Check.configSkeleton_Key_Check.config_pathSkeleton_Key_Check.contextSkeleton_Key_Check.get_requirements()Skeleton_Key_Check.make_subconfig()Skeleton_Key_Check.openSkeleton_Key_Check.run()Skeleton_Key_Check.set_open_method()Skeleton_Key_Check.unsatisfied()Skeleton_Key_Check.version
- volatility3.plugins.windows.ssdt module
- volatility3.plugins.windows.strings module
- volatility3.plugins.windows.svcscan module
- volatility3.plugins.windows.symlinkscan module
SymlinkScanSymlinkScan.build_configuration()SymlinkScan.configSymlinkScan.config_pathSymlinkScan.contextSymlinkScan.generate_timeline()SymlinkScan.get_requirements()SymlinkScan.make_subconfig()SymlinkScan.openSymlinkScan.run()SymlinkScan.scan_symlinks()SymlinkScan.set_open_method()SymlinkScan.unsatisfied()SymlinkScan.version
- volatility3.plugins.windows.vadinfo module
VadInfoVadInfo.MAXSIZE_DEFAULTVadInfo.build_configuration()VadInfo.configVadInfo.config_pathVadInfo.contextVadInfo.get_requirements()VadInfo.list_vads()VadInfo.make_subconfig()VadInfo.openVadInfo.protect_values()VadInfo.run()VadInfo.set_open_method()VadInfo.unsatisfied()VadInfo.vad_dump()VadInfo.version
- volatility3.plugins.windows.vadwalk module
- volatility3.plugins.windows.vadyarascan module
- volatility3.plugins.windows.verinfo module
- volatility3.plugins.windows.virtmap module