Trees | Indices | Help |
|
---|
|
Represents an open file, owned by a process.
Nested Classes | |
__metaclass__ Give each object a unique ID. (Inherited from rekall.obj.BaseObject) |
Instance Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
Class Variables | |
DTYPE_TO_HUMAN =
|
|
obj_name = <No name>
(Inherited from rekall.obj.BaseObject)
|
|
obj_parent = <No parent>
(Inherited from rekall.obj.BaseObject)
|
|
obj_producers = None hash(x) (Inherited from rekall.obj.BaseObject) |
Properties | |
fg_type Returns type of the fileglob (e.g. |
|
socket Return the associated socket if the dtype is for socket. |
|
vnode Return the associated vnode if the dtype is for vnode. |
|
human_name | |
human_type | |
indices Returns (usually 1) representation(s) of self usable as dict keys. (Inherited from rekall.obj.Struct) |
|
obj_end (Inherited from rekall.obj.BaseObject) | |
obj_size (Inherited from rekall.obj.Struct) | |
parents Returns all the parents of this object. (Inherited from rekall.obj.BaseObject) |
|
Inherited from |
Method Details |
Returns the correct struct with fg_type-specific information. This can be one of vnode, socket, shared memory or semaphore [1]. Of those four, we currently only get extra information for vnode and socket. For everything else, we return a NoneObject. [1]: https://github.com/opensource-apple/xnu/blob/10.9/bsd/sys/file_internal.h#L184 |
Class Variable Details |
DTYPE_TO_HUMAN
|
Property Details |
fg_typeReturns type of the fileglob (e.g. vnode, socket, etc.)
|
socketReturn the associated socket if the dtype is for socket.
|
vnodeReturn the associated vnode if the dtype is for vnode.
|
human_name
|
human_type
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:28:31 2017 | http://epydoc.sourceforge.net |