Trees | Indices | Help |
|
---|
|
An EWF capable address space.
In order for us to work we need: 1) There must be a base AS. 2) The first 6 bytes must be 45 56 46 09 0D 0A (EVF header)
NOTE: We currently only support opening a single segment file since it is passed from the base address space. This address space supports stacking.
Nested Classes | |
__metaclass__ Automatic Plugin Registration through metaclasses. (Inherited from rekall.addrspace.BaseAddressSpace) |
|
top_level_class This is the base class of all Address Spaces. (Inherited from rekall.addrspace.BaseAddressSpace) |
Instance Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
|||
|
|||
|
Class Variables | |
order = 20
|
|
CACHE_SIZE = 10
(Inherited from rekall.addrspace.CachingAddressSpaceMixIn)
|
|
CHUNK_SIZE = 32768
(Inherited from rekall.addrspace.CachingAddressSpaceMixIn)
|
|
classes =
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
classes_by_name =
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
name =
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
plugin_feature =
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
virtualized = False
(Inherited from rekall.addrspace.BaseAddressSpace)
|
|
volatile = False
(Inherited from rekall.addrspace.BaseAddressSpace)
|
Properties | |
Inherited from |
Method Details |
x.__init__(...) initializes x; see help(type(x)) for signature
|
Implement our own read method for caching. |
Generates a sequence of Run() objects. Each Run object describes a single range transformation from this address space to another address space at a potentially different mapped_offset. Runs are assumed to not overlap and are generated in increasing order. Args: start: The suggested start address we are interested in. This function may omit runs that lie entirely below this start address. Note: Runs are not adjusted to begin at the start address - it may be possible that this method returns a run which starts earlier than the specified start address.
|
|
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:27:59 2017 | http://epydoc.sourceforge.net |