Trees | Indices | Help |
|
---|
|
Find sysent by scanning around nsysent.
The production kernel no longer ships with the 'sysent' symbol, which is the address of the syscall switch table. However, because sysent and nsysent are initialized around the same time it works out that they are always near each other.
This is an old technique, documented around the internet, for example here: https://reverse.put.as/2010/11/27/a-semi-automated-way-to-find-sysent/
Nested Classes | |
__metaclass__ Automatic Plugin Registration through metaclasses. (Inherited from rekall.kb.ParameterHook) |
|
top_level_class A mechanism for automatically calculating a parameter. (Inherited from rekall.kb.ParameterHook) |
Instance Methods | |||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
|||
|
|||
|
Class Variables | |
name =
hash(x) |
|
SYSENT_REL_OFFSET = -16777216
|
|
LIMIT = 33554432
|
|
classes =
(Inherited from rekall.kb.ParameterHook)
|
|
classes_by_name =
(Inherited from rekall.kb.ParameterHook)
|
|
expiry = None hash(x) (Inherited from rekall.kb.ParameterHook) |
|
mode =
hash(x) (Inherited from rekall.plugins.darwin.common.DarwinOnlyMixin) |
|
plugin_feature =
(Inherited from rekall.kb.ParameterHook)
|
|
volatile = True
(Inherited from rekall.kb.ParameterHook)
|
Properties | |
Inherited from |
Method Details |
Derive the value of the parameter.
|
|
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:28:06 2017 | http://epydoc.sourceforge.net |