Trees | Indices | Help |
|
---|
|
Handle AFF4Map or AFF4Image type streams.
Since AFF4 volumes may contain multiple streams, we allow the stream to be specified inside the volume path. For example suppose the volume located at:
/home/mic/images/myimage.aff4
Contains a stream called PhysicalMemory, then we can specify the filename as:
/home/mic/images/myimage.aff4/PhysicalMemory
If we just specified the path to the volume, then this address space will pick the first AFF4 stream which has an aff4:category of lexicon.AFF4_MEMORY_PHYSICAL.
So if you have more than one physical memory stream in the same volume, you will need to specify the full path to the stream within the volume.
Nested Classes | |
__metaclass__ Automatic Plugin Registration through metaclasses. (Inherited from rekall.addrspace.BaseAddressSpace) |
|
top_level_class This is the base class of all Address Spaces. (Inherited from rekall.addrspace.BaseAddressSpace) |
Instance Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
|||
|
|||
|
Class Variables | |
order = 90
|
|
CACHE_SIZE = 10
(Inherited from rekall.addrspace.CachingAddressSpaceMixIn)
|
|
CHUNK_SIZE = 32768
(Inherited from rekall.addrspace.CachingAddressSpaceMixIn)
|
|
PAGE_MASK = -4096
(Inherited from rekall.addrspace.PagedReader)
|
|
PAGE_SIZE = 4096
(Inherited from rekall.addrspace.PagedReader)
|
|
classes =
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
classes_by_name =
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
name =
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
plugin_feature =
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
runs = None hash(x) (Inherited from rekall.addrspace.RunBasedAddressSpace) |
|
virtualized = False
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
volatile = False
(Inherited from rekall.addrspace.BaseAddressSpace)
|
Properties | |
Inherited from |
Method Details |
x.__init__(...) initializes x; see help(type(x)) for signature
|
Implement this method if you need to configure the session.
|
Returns the offset where the filename should be mapped. This function manages the session cache. By storing the file mappings in the session cache we can guarantee repeatable mappings. |
Return an address space for filename. |
Map the filename into the address space. If the filename is found in the AFF4 image, we return the offset in this address space corresponding to file_offset in the mapped file. If the file is not mapped, return None.
|
Return a string describing an address.
|
|
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:27:58 2017 | http://epydoc.sourceforge.net |