Trees | Indices | Help |
|
---|
|
List details on _MM_SESSION_SPACE (user logon sessions).
Windows uses sessions in order to separate processes. Sessions are used to separate the address spaces of windows processes.
Note that this plugin traverses the ProcessList member of the session object to list the processes - yet another list _EPROCESS objects are on.
Nested Classes | |
__metaclass__ Automatic Plugin Registration through metaclasses. (Inherited from rekall.plugin.Command) |
|
top_level_class A command can be run from the rekall command line. (Inherited from rekall.plugin.Command) |
Instance Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
|||
|
|||
|
|||
|
|||
|
|||
|
Class Variables | |
table_header =
hash(x) |
|
METHODS =
(Inherited from rekall.plugins.windows.common.WinProcessFilter)
|
|
PHYSICAL_AS_REQUIRED = True
(Inherited from rekall.plugin.PhysicalASMixin)
|
|
PROFILE_REQUIRED = True
(Inherited from rekall.plugin.ProfileCommand)
|
|
ROW_OPTIONS =
(Inherited from rekall.plugin.TypedProfileCommand)
|
|
classes =
(Inherited from rekall.plugin.Command)
|
|
classes_by_name =
(Inherited from rekall.plugin.Command)
|
|
error_status = None hash(x) (Inherited from rekall.plugin.Command) |
|
interactive = False
(Inherited from rekall.plugin.Command)
|
|
mode =
hash(x) (Inherited from rekall.plugins.windows.common.AbstractWindowsCommandPlugin) |
|
plugin_args = None hash(x) (Inherited from rekall.plugin.ArgsParserMixin) |
|
plugin_feature =
(Inherited from rekall.plugin.Command)
|
|
producer = False
(Inherited from rekall.plugin.Command)
|
|
table_options =
(Inherited from rekall.plugin.TypedProfileCommand)
|
Properties | |
filtering_requested (Inherited from rekall.plugins.windows.common.WinProcessFilter) | |
name (Inherited from rekall.plugin.Command) | |
Inherited from |
Method Details |
Generates unique _MM_SESSION_SPACE objects. Generates unique _MM_SESSION_SPACE objects referenced by active processes. Yields: _MM_SESSION_SPACE instantiated from the session space's address space. |
Get a _MM_SESSION_SPACE object by its ID. Args: session_id: the session ID to find. Returns: _MM_SESSION_SPACE instantiated from the session space's address space. |
Collect data that will be passed to renderer.table_row.
|
|
|
Class Variable Details |
table_headerhash(x)
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:29:07 2017 | http://epydoc.sourceforge.net |