Trees | Indices | Help |
|
---|
|
Fetch the PrivilegesHook table.
In Windows, privilege values are not constant, they are actually stored in kernel globals. We can see this kind of privilege check:
0xf800027b4e10 mov rcx, qword ptr [rip + 0x3a42a1] 0x7 nt!SeTcbPrivilege 0xf800027b4e17 call 0xf80002956a58 nt!SeSinglePrivilegeCheck
Demonstrating that the kernel reads the values in these locations (i.e. they are not hard coded). Although in reality they are never changed in runtime and probably do not really change between systems or versions.
This hook collects these values from the image.
Nested Classes | |
__metaclass__ Automatic Plugin Registration through metaclasses. (Inherited from rekall.kb.ParameterHook) |
|
top_level_class A mechanism for automatically calculating a parameter. (Inherited from rekall.kb.ParameterHook) |
Instance Methods | |||
|
|||
|
|||
Inherited from |
Class Methods | |||
|
|||
|
|||
|
Class Variables | |
name =
hash(x) |
|
classes =
(Inherited from rekall.kb.ParameterHook)
|
|
classes_by_name =
(Inherited from rekall.kb.ParameterHook)
|
|
expiry = None hash(x) (Inherited from rekall.kb.ParameterHook) |
|
mode =
hash(x) (Inherited from rekall.plugins.windows.common.AbstractWindowsParameterHook) |
|
plugin_feature =
(Inherited from rekall.kb.ParameterHook)
|
|
volatile = True
(Inherited from rekall.kb.ParameterHook)
|
Properties | |
Inherited from |
Method Details |
Derive the value of the parameter.
|
|
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:29:20 2017 | http://epydoc.sourceforge.net |