Trees | Indices | Help |
|
---|
|
Convert an existing Linux profile zip file. Since building the linux profile often happens on the target system, where Rekall is not normall running, we just convert the result of running Make in the tools/linux/ directory. See tools/linux/README for details. In short: - Run make in tools/linux/ directory. This will build module_dwarf.ko with debugging symbols. - If you have zip installed, the above step will create the required zip file. Otherwise Create a zip file manually with module_dwarf.ko and /boot/System.map-`uname -r` (Sometimes when running make not as the root user, its not possible to read the System.map file). Finally use this tool to convert the profile to a Rekall compatible profile.
Nested Classes | |
__metaclass__ Automatic Plugin Registration through metaclasses. (Inherited from rekall.plugins.tools.profile_tool.ProfileConverter) |
|
top_level_class Base class for converters. (Inherited from rekall.plugins.tools.profile_tool.ProfileConverter) |
Instance Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
|||
|
Class Variables | |
BASE_PROFILE_CLASS =
|
|
classes =
(Inherited from rekall.plugins.tools.profile_tool.ProfileConverter)
|
|
classes_by_name =
(Inherited from rekall.plugins.tools.profile_tool.ProfileConverter)
|
|
plugin_feature =
(Inherited from rekall.plugins.tools.profile_tool.ProfileConverter)
|
Properties | |
Inherited from |
Method Details |
Write all the components needed for the output profile.
|
|
|
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:29:00 2017 | http://epydoc.sourceforge.net |