Trees | Indices | Help |
|
---|
|
Nested Classes | |
__metaclass__ Give each object a unique ID. (Inherited from rekall.obj.BaseObject) |
Instance Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
Class Variables | |
obj_name = <No name>
(Inherited from rekall.obj.BaseObject)
|
|
obj_parent = <No parent>
(Inherited from rekall.obj.BaseObject)
|
|
obj_producers = None hash(x) (Inherited from rekall.obj.BaseObject) |
Properties | |
sharing_mode Returns the sharing mode of the backing vm_object. |
|
code_signed | |
last_shadow | |
start | |
end | |
vmo_object Return the vm_object instance for this entry. |
|
indices Returns (usually 1) representation(s) of self usable as dict keys. (Inherited from rekall.obj.Struct) |
|
obj_end (Inherited from rekall.obj.BaseObject) | |
obj_size (Inherited from rekall.obj.Struct) | |
parents Returns all the parents of this object. (Inherited from rekall.obj.BaseObject) |
|
Inherited from |
Method Details |
Find the underlying vnode object for the given vm_map_entry. xnu-2422.1.72/osfmk/vm/bsd_vm.c: 1339. |
Property Details |
sharing_modeReturns the sharing mode of the backing vm_object. This is losely adapted from vm_map.c, void vm_map_region_top_walk(), except we're not filling page counts for resident/reusable, etc.
|
code_signed
|
last_shadow
|
start
|
end
|
vmo_objectReturn the vm_object instance for this entry. There's an intermediate link called struct vm_map_entry. The members will be called either 'object' and 'vm_object' or 'vme_object' and 'vmo_object'. There is no easy heuristic for which it will be in a particular kernel version* so we just try both, since they mean the same thing. * The kernel version numbers could be identical for kernels built from a feature branch and a kernel build from trunk, and the two could be months apart. Furthermore, the profiles are generated not from the kernel itself but from a debug kit and can end up using out of date naming conventions.
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:28:32 2017 | http://epydoc.sourceforge.net |