Class ContextBuffer
Class ContextBuffer

A class to manage hits and create contiguous context buffers.

__init__(self, session)
x.__init__(...) initializes x; see help(type(x)) for signature
add_hit(self, string_name, hit_offset, value)
Yields pseudo_data for each context containing all hits.
process_owners_from_physical_address(self, address)
Get the process owner from the physical address.
get_contexts(self, offset)
Get some context about this offset.
We could use the ptov() or rammap() plugin but this is a very fast implementation which only cares about the identity of the owner.

We use this context to group similar yara hits into logical groups.

  a list of things which can be used as contexts - i.e. they are unique
  for all pages common within this context. Pages will be grouped by
  these contexts and evaluated together.