Repository navigation
Add dumping dirty pages to Linux Malfind #1853
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
ikelos
merged 11 commits into
volatilityfoundation:develop
from
tvanegro:dump_dirty_pages
Sep 28, 2025
Merged
Changes from 7 commits
Commits
Show all changes
11 commits
Select commit
Hold shift + click to select a range
7e77ee0
Adding dump dirty page feature
tvanegro 96fe242
Minor cleanup + comments
tvanegro ba9e136
Minor changes 2
tvanegro 53b3bd7
black
tvanegro e13b8f9
Fixing memory wrong memory offset in hex dump
tvanegro e4aa9af
version bump
tvanegro e7185b2
PR comments
tvanegro 438acdd
Update volatility3/framework/plugins/linux/malware/malfind.py
ikelos 1641253
Update volatility3/framework/plugins/linux/malware/malfind.py
ikelos d41afc4
Update volatility3/framework/plugins/linux/malware/malfind.py
ikelos f72b8ee
Update volatility3/framework/plugins/linux/malware/malfind.py
ikelos File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -18,7 +18,7 @@ class Malfind(interfaces.plugins.PluginInterface): | |
| """Lists process memory ranges that potentially contain injected code.""" | ||
|
|
||
| _required_framework_version = (2, 0, 0) | ||
| _version = (1, 0, 3) | ||
| _version = (1, 0, 4) | ||
|
|
||
| @classmethod | ||
| def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface]: | ||
|
|
@@ -37,6 +37,16 @@ def get_requirements(cls) -> List[interfaces.configuration.RequirementInterface] | |
| element_type=int, | ||
| optional=True, | ||
| ), | ||
| requirements.IntRequirement( | ||
| name="dump-size", | ||
| description="Amount of bytes to dump for each dirty region/page found - Default 64 bytes", | ||
| optional=True, | ||
| ), | ||
| requirements.BooleanRequirement( | ||
| name="dump-page", | ||
| description="Dump each dirty page and content - Default off", | ||
| optional=True, | ||
|
ikelos marked this conversation as resolved.
|
||
| ), | ||
| ] | ||
|
|
||
| def _list_injections( | ||
|
|
@@ -51,14 +61,36 @@ def _list_injections( | |
|
|
||
| proc_layer = self.context.layers[proc_layer_name] | ||
|
|
||
| dump_size = self.config.get("dump-size", None) or 64 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. this and the dump-page one should use the
ikelos marked this conversation as resolved.
Outdated
|
||
|
|
||
| # Dumping page defaults to off, as in case a whole r-xp region is dirty | ||
| # this would likely dump 1000's of pages which might not always be wise nor necessary | ||
|
|
||
| dump_page = self.config.get("dump-page") or False | ||
|
ikelos marked this conversation as resolved.
Outdated
|
||
|
|
||
| for vma in task.mm.get_vma_iter(): | ||
| vma_name = vma.get_name(self.context, task) | ||
| vollog.debug( | ||
| f"Injections : processing PID {task.pid} : VMA {vma_name} : {hex(vma.vm_start)}-{hex(vma.vm_end)}" | ||
| ) | ||
|
|
||
| # If is_suspicious returns true, this means at least one page | ||
| # in the region is dirty. If dump_page is true, then we dump | ||
| # all dirty pages | ||
|
|
||
| if vma.is_suspicious(proc_layer) and vma_name != "[vdso]": | ||
| data = proc_layer.read(vma.vm_start, 64, pad=True) | ||
| yield vma, vma_name, data | ||
| malicious_pages = vma.get_malicious_pages(proc_layer) | ||
| offset = 0 | ||
| if dump_page: | ||
| # Dumping each dirty page | ||
| for page_addr in malicious_pages: | ||
| offset = page_addr - vma.vm_start | ||
| data = proc_layer.read(page_addr, dump_size, pad=True) | ||
| yield vma, f"{vma_name}, page address: {page_addr:#x}, offset: {offset:#x}", data, offset | ||
| else: | ||
| # Original behaviour - Dump the start of the region (not necessarily matching the dirty page) | ||
| data = proc_layer.read(vma.vm_start, dump_size, pad=True) | ||
| yield vma, vma_name, data, offset | ||
|
|
||
| def _generator(self, tasks): | ||
| # determine if we're on a 32 or 64 bit kernel | ||
|
|
@@ -70,13 +102,15 @@ def _generator(self, tasks): | |
| for task in tasks: | ||
| process_name = utility.array_to_string(task.comm) | ||
|
|
||
| for vma, vma_name, data in self._list_injections(task): | ||
| for vma, vma_name, data, offset in self._list_injections(task): | ||
| if is_32bit_arch: | ||
| architecture = "intel" | ||
| else: | ||
| architecture = "intel64" | ||
|
|
||
| disasm = renderers.Disassembly(data, vma.vm_start, architecture) | ||
| disasm = renderers.Disassembly( | ||
| data, vma.vm_start + offset, architecture | ||
| ) | ||
|
|
||
| yield ( | ||
| 0, | ||
|
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.