Trees | Indices | Help |
|
---|
|
Detect the Darwin version using the index.
To work around KASLR, we have an index of known symbols' offsets relative to the Catfish string, along with the data we expect to find at those offsets. Profile similarity is the percentage of these symbols that match as expected.
Ideally, we'd like a 100% match, but in case we don't have the exact profile, we'll make do with anything higher than 0% that can resolve the DTB.
Nested Classes | |
find_dtb_impl Tries to find the DTB address for the Darwin/XNU kernel. |
|
__metaclass__ Automatic Plugin Registration through metaclasses. (Inherited from rekall.plugins.guess_profile.DetectionMethod) |
|
top_level_class A baseclass to implement autodetection methods. (Inherited from rekall.plugins.guess_profile.DetectionMethod) |
Instance Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
|||
|
Class Variables | |
name =
hash(x) |
|
classes =
(Inherited from rekall.plugins.guess_profile.DetectionMethod)
|
|
classes_by_name =
(Inherited from rekall.plugins.guess_profile.DetectionMethod)
|
|
order = 100
(Inherited from rekall.plugins.guess_profile.DetectionMethod)
|
|
plugin_feature =
(Inherited from rekall.plugins.guess_profile.DetectionMethod)
|
Properties | |
Inherited from |
Method Details |
x.__init__(...) initializes x; see help(type(x)) for signature
|
Returns a list of keywords which will be searched. Each time the keyword is matched, this instance will be called to attempt detection.
|
Gets called for each hit. If a profile matches, return it, otherwise None.
|
|
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:28:16 2017 | http://epydoc.sourceforge.net |