ããã¯ãUbuntu OnlineãFedora OnlineãWindows ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒããŸã㯠MAC OS ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒãªã©ã®è€æ°ã®ç¡æãªã³ã©ã€ã³ ã¯ãŒã¯ã¹ããŒã·ã§ã³ã® XNUMX ã€ã䜿çšããŠãOnWorks ç¡æãã¹ãã£ã³ã° ãããã€ããŒã§å®è¡ã§ããã³ãã³ãã®å€åæ§ã§ãã
ããã°ã©ã ïŒ
NAME
ä¹±é«äž - é«åºŠãªã¡ã¢ãªãã©ã¬ã³ãžãã¯ãã¬ãŒã ã¯ãŒã¯
SYNOPSIS
ä¹±é«äž [ãªãã·ã§ã³]
ä¹±é«äž -f [ç»å] - ãããã£ãŒã«=[ãããã£ãŒã«] [ãã©ã°ã€ã³]
DESCRIPTION
ãã©ãã£ãªã㣠ãã¬ãŒã ã¯ãŒã¯ã¯ã次ã®æ å ±ãæœåºããããã®å®å šã«ãªãŒãã³ãªããŒã«ã®ã³ã¬ã¯ã·ã§ã³ã§ãã
æ®çºæ§ã¡ã¢ãª (RAM) ãµã³ãã«ããã®ããžã¿ã« ã¢ãŒãã£ãã¡ã¯ãã ãã©ã¬ã³ãžãã¯åæã«åœ¹ç«ã¡ãŸãã
æœåºæè¡ã¯ãã·ã¹ãã ããå®å šã«ç¬ç«ããŠå®è¡ãããŸãã
調æ»ãããŠããŸãããã·ã¹ãã ã®å®è¡æã®ç¶æ ã«å¯ŸããåäŸã®ãªãå¯èŠæ§ãæäŸãããŸãã
Volatility ã¯ãMS WindowsãLinuxãããã³ MAC OSX ã®ããã€ãã®ããŒãžã§ã³ããµããŒãããŠããŸãã
MS Windows:
· 32 ããã Windows XP Service Pack 2 ããã³ 3
· 32 ããã Windows 2003 Server Service Pack 0ã1ã2
· 32 ããã Windows Vista Service Pack 0ã1ã2
· 32 ããã Windows 2008 Server Service Pack 1ã2 (SP0 ã¯ãããŸãã)
· 32 ããã Windows 7 Service Pack 0ã1
· 32 ããã Windows 8ã8.1ãããã³ 8.1 Update 1
ã»32ãããWindows 10ïŒåæãµããŒãïŒ
· 64 ããã Windows XP Service Pack 1 ããã³ 2 (SP0 ã¯ãããŸãã)
· 64 ããã Windows 2003 Server Service Pack 1 ããã³ 2 (SP0 ã¯ãããŸãã)
· 64 ããã Windows Vista Service Pack 0ã1ã2
· 64 ããã Windows 2008 Server Service Pack 1 ããã³ 2 (SP0 ã¯ãããŸãã)
· 64 ããã Windows 2008 R2 Server Service Pack 0 ããã³ 1
· 64 ããã Windows 7 Service Pack 0 ããã³ 1
· 64 ããã Windows 8ã8.1ãããã³ 8.1 Update 1
· 64 ããã Windows Server 2012 ããã³ 2012 R2
ã»64ãããWindows 10ïŒåæãµããŒãïŒ
LinuxïŒ
· 32 ããã Linux ã«ãŒãã« 2.6.11 ïœ 4.2.3
· 64 ããã Linux ã«ãŒãã« 2.6.11 ïœ 4.2.3
· OpenSuSEãUbuntuãDebianãCentOSãFedoraãMandriva ãªã©
Mac OSXïŒ
· 32 ããã 10.5.x Leopard (64 ããã 10.5 ã¯ãµãŒããŒã®ã¿ã§ããããµããŒããããŠããŸãã)
· 32 ããã 10.6.x Snow Leopard
· 64 ããã 10.6.x Snow Leopard
· 32 ããã 10.7.x ã©ã€ãªã³
· 64 ããã 10.7.x ã©ã€ãªã³
· 64 ããã 10.8.x Mountain Lion (32 ããã ããŒãžã§ã³ã¯ãããŸãã)
· 64 ããã 10.9.x Mavericks (32 ããã ããŒãžã§ã³ã¯ãããŸãã)
· 64 ããã 10.10.x Yosemite (32 ããã ããŒãžã§ã³ã¯ãããŸãã)
· 64 ããã 10.11.x El Capitan (32 ããã ããŒãžã§ã³ã¯ãããŸãã)
ãµããŒããããŠããã¡ã¢ãªåœ¢åŒã¯æ¬¡ã®ãšããã§ãã
ã»çç·ç¶ãµã³ãã«(dd)
· ãã€ãããŒã·ã§ã³ãã¡ã€ã«
ã»ã¯ã©ãã·ã¥ãã³ããã¡ã€ã«
· VirtualBox ELF64 ã³ã¢ãã³ã
· VMware ã®ä¿åãããç¶æ ããã³ã¹ãããã·ã§ãã ãã¡ã€ã«
ã»EWF圢åŒïŒE01ïŒ
ã»LiMEïŒLinux Memory ExtractorïŒåœ¢åŒ
ã»ããããã¡ã€ã«åœ¢åŒ
· QEMUä»®æ³ãã·ã³ã®ãã³ã
ã» ç«ç·
ã»HPAK(FDPro)
ãµããŒããããŠããã¢ãã¬ã¹ç©ºé (RAM ã¿ã€ã) ã¯æ¬¡ã®ãšããã§ãã
· AMD64PagesMemory - æšæº AMD 64 ããã ã¢ãã¬ã¹ç©ºé
· ArmAddressSpace - ARM ããã»ããµã®ã¢ãã¬ã¹ç©ºé
· FileAddressSpace - ããã¯çŽæ¥ãã¡ã€ã« AS ã§ã
· HPAKAddressSpace - ãã® AS 㯠HPAK 圢åŒããµããŒãããŸã
· IA32PaggedMemoryPae - ãã®ã¯ã©ã¹ã¯ãIA-32 PAE ããŒãžã³ã° ã¢ãã¬ã¹ç©ºéãå®è£ ããŸãã
ããã¯è²¬ä»»ããã
· IA32PagesMemory - æšæº IA-32 ããŒãžã³ã° ã¢ãã¬ã¹ç©ºé
· LimeAddressSpace - Lime ã®ã¢ãã¬ã¹ç©ºé
· MachOAddressSpace - atc-ny ã¡ã¢ãªããµããŒãããããã® mach-o ãã¡ã€ã«ã®ã¢ãã¬ã¹ç©ºé
èªè
· OSXPmemELF - ãã® AS 㯠VirtualBox ELF64 ã³ã¢ãã³ã圢åŒããµããŒãããŸã
· QemuCoreDumpElf - ãã® AS 㯠Qemu ELF32 ããã³ ELF64 ã³ã¢ãã³ã圢åŒããµããŒãããŸã
· VirtualBoxCoreDumpElf64 - ãã® AS 㯠VirtualBox ELF64 ã³ã¢ãã³ã圢åŒããµããŒãããŸã
· VMWareAddressSpace - ãã® AS 㯠VMware ã¹ãããã·ã§ãã (VMSS) ãšä¿åãããç¶æ ããµããŒãããŸãã
(VMSS) ãã¡ã€ã«
· VMWareMetaAddressSpace - ãã® AS ã¯ãVMSN/VMSS ã«ãã VMEM ãã©ãŒãããããµããŒãããŸãã
· WindowsCrashDumpSpace32 - ãã® AS 㯠Windows ã¯ã©ãã·ã¥ ãã³ã ãã©ãŒãããããµããŒãããŸãã
· WindowsCrashDumpSpace64BitMap - ãã® AS 㯠Windows BitMap ã¯ã©ãã·ã¥ ãã³ãããµããŒãããŸãã
圢åŒã§ã¢ãŒã«ã€ããããããžã§ã¯ããä¿åããŸãïŒ
· WindowsCrashDumpSpace64 - ãã® AS 㯠Windows ã¯ã©ãã·ã¥ ãã³ã ãã©ãŒãããããµããŒãããŸãã
· WindowsHiberFileSpace32 - ãã㯠Windows ã®äŒæ¢ç¶æ ã®ã¢ãã¬ã¹ç©ºéã§ã
äŒæ¢ç¶æ ãã¡ã€ã«
ãã¹ãçšã®ãµã³ãã« ã¡ã¢ãª ã€ã¡ãŒãžã次ã®å Žæã«ãããŸãã
https://github.com/volatilityfoundation/ä¹±é«äž/wiki/ã¡ã¢ãªãµã³ãã«ã
OPTIONS
-NSã - å©ããŠ
䜿çšå¯èœãªãã¹ãŠã®ãªãã·ã§ã³ãšãã®ããã©ã«ãå€ããªã¹ãããŸãã ããã©ã«ãå€ã¯æ¬¡ã®ããã«èšå®ã§ããŸãã
èšå®ãã¡ã€ã« (/etc/volatilityrc)ã
--conf-file=/root/.volatilityrc
ãŠãŒã¶ãŒããŒã¹ã®æ§æãã¡ã€ã«ã
-NSã - ãããã°
æ®çºæ§ããããã°ããŸãã
--plugins=ãã©ã°ã€ã³
NEW ãã©ã°ã€ã³ 䜿çšãããã£ã¬ã¯ã㪠(ã³ãã³åºåã)ã
- æ å ± ç»é²ãããŠãããã¹ãŠã®ãªããžã§ã¯ãã«é¢ããæ å ±ãåºåããŸãã
--cache-directory=/root/.cache/volatility
ãã£ãã·ã¥ ãã¡ã€ã«ãä¿åããããã£ã¬ã¯ããªã
- ãã£ãã·ã¥
ãã£ãã·ã¥ã䜿çšããŸãã
--tz=TZ
pytz (ã€ã³ã¹ããŒã«ãããŠããå Žå) ãŸã㯠tzset ã䜿çšããŠã¿ã€ã ã¹ã¿ã³ãã衚瀺ããããã®ã¿ã€ã ãŸãŒã³ãèšå®ããŸã
-f ãã¡ã€ã«åã --filename = FILENAME
ãã¡ã€ã«ãéããšãã«äœ¿çšãããã¡ã€ã«å ç»å.
--profile=WinXPSP2x86
ããŒããããããã¡ã€ã«ã®åå (äœ¿çš - æ å ± ãµããŒããããŠãããããã¡ã€ã«ã®ãªã¹ããåç §ããŠãã ãã)ã
-l äœçœ®ã --location=å Žæ
ã¢ãã¬ã¹ç©ºéã®ããŒãå ãšãªã URN ã®å Žæã
-wã - æžããŸã
æžã蟌ã¿ãµããŒããæå¹ã«ããŸãã
--dtb=DTB
DTB ã¢ãã¬ã¹ã
--shift=ã·ãã
Mac KASLR ã®ã·ãã ã¢ãã¬ã¹ã
--output=ããã¹ã
ãã®åœ¢åŒã§åºåããŸãã
--output-file=OUTPUT_FILE
åºåããã®ãã¡ã€ã«ã«æžã蟌ã¿ãŸãã
-vã -詳现
詳现ãªæ å ±ã
-g KDBGã --kdbg=KDBG
ç¹å®ã® KDBG ä»®æ³ã¢ãã¬ã¹ãæå®ããŸãã 64 ããã Windows 8 以éã®å Žåãããã¯
KdCopyDataBlock ã®ã¢ãã¬ã¹ã
- å
çããããããã¡ã€ã«ã®äœ¿çšã匷å¶ããŸãã
-k KPCRã --kpcr=KPCR
ç¹å®ã® KPCR ã¢ãã¬ã¹ãæå®ããŸãã
--cookie=ã¯ãããŒ
nt!ObHeaderCookie ã®ã¢ãã¬ã¹ãæå®ããŸã (Windows 10 ã®ã¿æå¹)ã
PLUGINS ãã㊠ãããã£ãŒã«
ãµããŒããããŠãã ãã©ã°ã€ã³ ã³ãã³ã '$ ã䜿çšãããšãã³ãã³ããšãããã¡ã€ã«ã衚瀺ã§ããŸãã
ä¹±é«äž - æ å ±'ã Linux ããã³ MAC OSX ã§èš±å¯ãããŠãããã©ââã°ã€ã³ã«ã¯ãlinux_ããä»ããŠããããšã«æ³šæããŠãã ããã
ããã³ãmac_ããã¬ãã£ãã¯ã¹ã ãããã®ãã¬ãã£ãã¯ã¹ã®ãªããã©ã°ã€ã³ã¯ MS Windows çšã«èšèšãããŠããŸãã
ãããã¡ã€ã«ã¯ãéçšã·ã¹ãã ãç解ããããã« Volatility ã䜿çšãããããã§ãã èš±å¯ãããMS
Windows ãããã¡ã€ã«ã¯ Volatility ã«ãã£ãŠæäŸãããŸãã
Linux ããã³ MAC OSX çšã®ç¬èªã®ãããã¡ã€ã«ãäœæããå¿ èŠããããŸãã ããã«ã€ããŠã¯ãDebian ã·ã¹ãã ã§ã¯æ¬¡ãåç §ããŠãã ããã
ã«ãã£ãŠæäŸããã README.Debian ãã¡ã€ã« ä¹±é«äž-ããŒã«ããã±ãŒãžã
MS Windows ã§ã¯ãOS ã®çš®é¡ã確èªããããã«æ¬¡ã®ã³ãã³ãã䜿çšã§ããŸãã
$ ãã©ãã£ãªã㣠-f ç»åæ å ±
or
$ ãã©ãã£ãªã㣠-f kdbgscan
ENVIRONMENT å€æ°
GNU/Linux ãŸã㯠OS X ã·ã¹ãã ã§ã¯ã次ã®å€æ°ãèšå®ã§ããŸãã
· VOLATILITY_PROFILE - ããã©ã«ããšããŠäœ¿çšãããããã¡ã€ã«ãæå®ããŸãã
äžèŠãªã- ãããã£ãŒã«' ãªãã·ã§ã³.
· VOLATILITY_LOCATION - ã®ãã¹ãæå®ããŸãã ç»åã ã€ãŸããVolatility ã³ãã³ã
' ã«ãããã¡ã€ã«åã¯å¿ èŠãããŸãã-f' ãªãã·ã§ã³.
· VOLATILITY_KDBG - KDBG ã¢ãã¬ã¹ãæå®ããŸãã è¿œå æé ããã£ãšèŠã
詳现ã
ãã®ä» ãã©ã°ã€ã³ ãã®æ¹æ³ã§ã¯ãKPCRãDTBãPLUGINS ãªã©ã®ãã©ã°ãå©çšã§ããŸãã ãã€
å€æ°ããšã¯ã¹ããŒãããå Žåã¯ããã©ã°åã®åã« VOLATILITY_ ãä»ããã ãã§ã (äŸ:
VOLATILITY_KPCR)ã ãã以å€ã®å Žåããã©ã°åã¯ããã©ã°ã
èšå®ãã¡ã€ã«
ååã«ã¹ããŒã¹ä»¥äžãå«ãŸãããã¹ãããå Žåãã¹ããŒã¹ã¯ %20 ã«çœ®ãæããå¿ èŠããããŸãã
代ããã« (äŸ: LOCATION=file:///tmp/my%20image.img)ã
äŸïŒ
$export VOLATILITY_PROFILE=Win7SP0x86
$export VOLATILITY_LOCATION=file:///tmp/myimage.img
$ ãšã¯ã¹ããŒã VOLATILITY_KDBG=0x82944c28
CONFIGURATION ãã¡ã€ã«
æ§æãã¡ã€ã«ã¯éåžžãçŸåšã®ãã£ã¬ã¯ããªã«ãããvolatilityrcããŸãã¯
'~/.volatilityrc' ãŠãŒã¶ãŒã®ããŒã ãã£ã¬ã¯ããªããŸãã¯ãŠãŒã¶ãŒãæå®ãããã¹ã§ã --conf-
file ãªãã·ã§ã³ã ãã¡ã€ã«ã®å 容ã®äŸã以äžã«ç€ºããŸãã
[ããã©ã«ã]
ãããã¡ã€ã«=Win7SP0x86
LOCATION=file:///tmp/myimage.img
KDBG=0x82944c28
ãã®ä» ãã©ã°ã€ã³ ãã®æ¹æ³ã§ã¯ãKPCRãDTBãPLUGINS ãªã©ã®ãã©ã°ãå©çšã§ããŸãã ãã€
å€æ°ããšã¯ã¹ããŒãããå Žåã¯ããã©ã°åã®åã« VOLATILITY_ ãä»ããã ãã§ã (äŸ:
VOLATILITY_KPCR)ã ãã以å€ã®å Žåããã©ã°åã¯ããã©ã°ã
èšå®ãã¡ã€ã«
ååã«ã¹ããŒã¹ä»¥äžãå«ãŸãããã¹ãããå Žåãã¹ããŒã¹ã¯ %20 ã«çœ®ãæããå¿ èŠããããŸãã
代ããã« (äŸ: LOCATION=file:///tmp/my%20image.img)ã
EXTRA æç¶ã
ã¿ã€ã ãŸãŒã³ã®èšå®
ã¡ã¢ãªããæœåºãããã¿ã€ã ã¹ã¿ã³ãã¯ãã·ã¹ãã ã®ããŒã«ã«æéãŸãã¯äžçæã®ããããã«ãªããŸãã
åº§æš (UTC)ã UTC ã®å ŽåãVolatility ã¯ããããæéå ã«è¡šç€ºããããã«æ瀺ã§ããŸãã
ã¢ããªã¹ããéžæãããŸãŒã³ã ã¿ã€ã ãŸãŒã³ãéžæããã«ã¯ãæšæºã¿ã€ã ãŸãŒã³ã®ããããã䜿çšããŸã
åå (ã¢ã¡ãªã«/ãµã³ããŠãããšãŒããã/ãã³ãã³ãç±³åœ/æ±éšããŸãã¯ã»ãšãã©ã®ãªã«ãœã³ã®ã¿ã€ã ãŸãŒã³ãªã©)
--tz=TIMEZONE ãã©ã°ã
Volatility ã¯ãã€ã³ã¹ããŒã«ãããŠããå Žå㯠pytz ã䜿çšããããšããã€ã³ã¹ããŒã«ãããŠããªãå Žå㯠tzset ã䜿çšããŸãã
ã¿ã€ã ãŸãŒã³ãæå®ããŠããã·ã¹ãã ã®çŸå°æéã®è¡šç€ºæ¹æ³ã«ã¯åœ±é¿ããªãããšã«æ³šæããŠãã ããã ããã
UTC ããŒã¹ã§ããããšãããã£ãŠããæå»ãç¹å®ããå Žåã¯ãåé¡ãã©ãã«ãŒã«åé¡ãšããŠãã¡ã€ã«ããŠãã ããã
ããã©ã«ãã§ã¯ã_EPROCESS ã® CreateTime ããã³ ExitTime ã¿ã€ã ã¹ã¿ã³ã㯠UTC ã§ãã
DTBã®èšå®
DTB (ãã£ã¬ã¯ã㪠ããŒãã« ããŒã¹) ã¯ãVolatility ãä»®æ³ã¢ãã¬ã¹ãç©çã¢ãã¬ã¹ã«å€æããããã«äœ¿çšãããã®ã§ãã
ã¢ãã¬ã¹ã ããã©ã«ãã§ã¯ãã«ãŒãã« DTB ã (ã¢ã€ãã«/ã·ã¹ãã ããã»ã¹ãã) 䜿çšãããŸãã ã䜿çšãããå Žåã¯ã
å¥ã®ããã»ã¹ã® DTB ã§ããŒã¿ã«ã¢ã¯ã»ã¹ããå Žåã¯ã--dtb=ADDRESS ã«ã¢ãã¬ã¹ãæå®ããŸãã
KDBG ã¢ãã¬ã¹ã®èšå® (ãã㯠Windows ã®ã¿) ãªãã·ã§ã³)
ãã©ãã£ãªãã£ã¯ãããŒãã³ãŒãã£ã³ã°ããã眲åãKDBGããš
äžé£ã®å¥å šæ§ãã§ãã¯ã ãããã®çœ²åã¯ããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ãæ©èœããããã«éèŠã§ã¯ãããŸããã
ãããã£ãŠããã«ãŠã§ã¢ã¯ã
ãµã€ã³ã ããã«ãå Žåã«ãã£ãŠã¯ãè€æ°ã®ã_KDDEBUGGER_DATA64ããååšããå¯èœæ§ããããŸã (
ããšãã°ãOS ã®ã¡ãžã£ãŒ ã¢ããããŒããé©çšããåèµ·åããªãã£ãå Žåãªã©ïŒãæ··ä¹±ãåŒãèµ·ããã次ã®ãããªåé¡ãçºçããå¯èœæ§ããããŸãã
ããã»ã¹ãã¢ãžã¥ãŒã«ã®ãªã¹ããééã£ãŠãããªã©ã®åé¡ãçºçããŸãã äœæããããã°
ã_KDDEBUGGER_DATA64ããè¿œå ãããšã--kdbg=ADDRESS ã§æå®ã§ããããã«ããèªååããã
ã¹ãã£ã³ããŸãã 詳现ã«ã€ããŠã¯ãkdbgscan ãã©ã°ã€ã³ãåç §ããŠãã ããã
KPCR ã¢ãã¬ã¹ã®èšå® (ãã㯠Windows ã®ã¿) ãªãã·ã§ã³)
ã·ã¹ãã äžã® CPU ããšã« XNUMX ã€ã® KPCR (ã«ãŒãã« ããã»ããµå¶åŸ¡é å) ããããŸãã ããçšåºŠã®ãã©ãã£ãªãã£
ãã©ã°ã€ã³ã¯ããã»ããµããšã®æ å ±ã衚瀺ããŸãã ãããã£ãŠãç¹å®ã® CPU ã®ããŒã¿ã衚瀺ãããå Žåã¯ã
ããšãã°ãCPU 3 ã®ä»£ããã« CPU 1 ãæå®ãããšã--kpcr=ADDRESS ã䜿çšããŠãã® CPU ã® KPCR ã®ã¢ãã¬ã¹ãæž¡ãããšãã§ããŸãã
ãã¹ãŠã® CPU ã® KPCR ãèŠã€ããã«ã¯ãkpcrscan ãã©ã°ã€ã³ãåç §ããŠãã ããã ãŸããVolatility 2.2 以éã§ã¯ã
idt ã gdt ãªã©ã®ãã©ã°ã€ã³ã®å€ãã¯ãKPCR ã®ãªã¹ããèªåçã«ç¹°ãè¿ãåŠçããŸãã
æžã蟌ã¿ãµããŒããæå¹ã«ãã
Volatility ã§ã®æžã蟌ã¿ãµããŒãã¯æ³šæããŠäœ¿çšããå¿ èŠããããŸãã ãããã£ãŠãå®éã«æå¹ã«ããã«ã¯ã次ã®ããšãè¡ãå¿ èŠããããŸãã
ã³ãã³ãã©ã€ã³ã§ --write ãšå ¥åããã ãã§ãªãã次ã®ãããªè³ªåã«çããŠããã¹ã¯ãŒãããå ¥åããå¿ èŠããããŸãã
ãšããããã³ããã衚瀺ãããŸãã ã»ãšãã©ã®å Žåãæžã蟌ã¿ãµããŒãã¯äœ¿çšããªãã»ããããã§ãããã
ã¡ã¢ãªãã³ãå ã®ããŒã¿ã®ç ŽæãŸãã¯å€æŽã ãã ãããããå¯èœã«ããç¹æ®ãªã±ãŒã¹ãååšããŸãã
æ¬åœã«èå³æ·±ãæ©èœã§ãã ããšãã°ã次ã®ããã«ããŠã©ã€ã ã·ã¹ãã ããç¹å®ã®ãã«ãŠã§ã¢ãé§é€ã§ããŸãã
Firewire çµç±ã§ RAM ã«æžã蟌ããããã€ãã«ããããé©çšããããšã§ãããã¯ãããã¯ãŒã¯ã¹ããŒã·ã§ã³ã«äŸµå ¥ããå¯èœæ§ããããŸãã
winlogon DLLã
è¿œå æå® ãã©ã°ã€ã³ ãã£ã¬ã¯ããª
Volatility ã®ãã©ã°ã€ã³ ã¢ãŒããã¯ãã£ã§ã¯ãè€æ°ã®ãã£ã¬ã¯ããªãããã©ã°ã€ã³ ãã¡ã€ã«ãäžåºŠã«ããŒãã§ããŸãã ã®äžã«
Volatility ãœãŒã¹ ã³ãŒããã»ãšãã©ã®ãã©ã°ã€ã³ã¯ Volatility/plugins ã«ãããŸãã ãã ããå¥ã®ãã®ããããŸã
ãµãŒãããŒãã£éçºè ããã®è²¢ç®ã®ããã«äºçŽãããŠãããã£ã¬ã¯ã㪠(volatility/contrib)ããŸãã¯
ãµããŒãã匱ããããã©ã«ãã§ã¯æå¹ã«ãªã£ãŠããªããã©ã°ã€ã³ã ãããã®ãã©ã°ã€ã³ã«ã¢ã¯ã»ã¹ããã«ã¯ã
ã³ãã³ãã©ã€ã³ã§ --plugins=contrib/plugins ãšå ¥åããŸãã å¥ã®ãã£ã¬ã¯ããªãäœæããããšãã§ããŸã
ã³ã¢å ã®ãã¡ã€ã«ãè¿œå /åé€/å€æŽããããšãªã管çã§ããç¬èªã®ãã©ã°ã€ã³
æ®çºæ§ãã£ã¬ã¯ããªã
泚æïŒ
* Debian ã·ã¹ãã ã§ã¯ãcontrib/plugins ãã£ã¬ã¯ããªã¯ /usr/share/volatility/contrib/plugins ã«ãããŸãã
* __init__.py ãã¡ã€ã« (空ã§ãããŸããŸãã) ãååšããéãããµããã£ã¬ã¯ããªããã©ããŒã¹ãããŸãã
ãããã®äžã§ã
* --plugins ãžã®ãã©ã¡ãŒã¿ã¯ã次ã®ãããªãã©ã°ã€ã³ãå«ã zip ãã¡ã€ã«ã«ããããšãã§ããŸãã
--plugins=myplugins.zip ãšããŠã ãã©ã°ã€ã³ã®ããŒãæ¹æ³ã«ãããå€éšãã©ã°ã€ã³ ãã£ã¬ã¯ããª
ãŸã㯠zip ãã¡ã€ã«ã¯ããã©ã°ã€ã³åºæã®åŒæ° (ãã¡ã€ã«åãå«ã) ã®åã«æå®ããå¿ èŠããããŸãã
ãã©ã°ã€ã³ïŒã äŸïŒ
$ volatility --plugins=contrib/plugins -f XPSP3x86.vmem ã®äŸ
åºå圢åŒã®éžæ
ããã©ã«ãã§ã¯ããã©ã°ã€ã³ã¯æšæºåºåãžã®ããã¹ãã¬ã³ãã©ãŒã䜿çšããŸãã ãã¡ã€ã«ã«ãªãã€ã¬ã¯ããããå Žåã¯ã
ãã¡ãããã³ã³ãœãŒã«ã®ãªãã€ã¬ã¯ã (ã€ãŸã > out.txt) ã䜿çšããããšãã--output-file=out.txt ã䜿çšããããšãã§ããŸãã
--output=FORMAT ãéžæã§ããçç±ã¯ããã©ã°ã€ã³ãåºåã HTML ãšããŠã¬ã³ããªã³ã°ã§ããããã«ããããã§ãã
JSONãSQLããŸãã¯ä»»æã®ãã®ãéžæããŸãã ãã ãããããã®ä»£æ¿åºå圢åŒãåãããã©ã°ã€ã³ã¯ãããŸãã
䜿çšããããã«äºåã«èšå®ãããŠãããããrender_htmlãrender_jsonãrender_sql ãšããååã®é¢æ°ãè¿œå ããå¿ èŠããããŸãã
--output=HTML ã䜿çšããåã«ããããããåãã©ã°ã€ã³ã«èšå®ããŸãã
ãã©ã°ã€ã³åºæã®ãªãã·ã§ã³
å€ãã®ãã©ã°ã€ã³ã¯ãã°ããŒãã« ãªãã·ã§ã³ããç¬ç«ããç¬èªã®åŒæ°ãåãå ¥ããŸãã èŠãã«ã¯
䜿çšå¯èœãªãªãã·ã§ã³ã®ãªã¹ãã衚瀺ããã«ã¯ãã³ãã³ãã©ã€ã³ã§ãã©ã°ã€ã³åãš -h/--help ã®äž¡æ¹ãå ¥åããŸãã
$ ãã©ãã£ãªã㣠dlllist -h
ãããã°ã¢ãŒã
Volatility ã§æåŸ ã©ããã«äœããèµ·ãã£ãŠããªãå Žåã¯ã-d/--debug ãæå®ããŠã³ãã³ããå®è¡ããŠã¿ãŠãã ããã
ããã«ããããããã° ã¡ãã»ãŒãžãæšæºãšã©ãŒã«åºåã§ããããã«ãªããŸãã ããå€ãã®ãããã° ã¬ãã«ã«ããã«ã¯ã次ã®ããã«äœ¿çšããŸãã
pdb ãããã¬ãŒ)ãã³ãã³ãã« -d -d -d ãè¿œå ããŸãã
Volatility ãã©ã€ãã©ãªãšããŠäœ¿çšãã
Volatility ãã©ã€ãã©ãªãšããŠäœ¿çšããããšã¯å¯èœã§ããã(
æªæ¥ïŒã çŸåšãPython ã¹ã¯ãªãããã Volatility ãã€ã³ããŒãããã«ã¯ã次ã®ãµã³ãã« ã³ãŒãã䜿çšã§ããŸãã
$ãã€ãœã³
>>> volatility.conf ã conf ãšããŠã€ã³ããŒã
>>> volatility.registry ãã¬ãžã¹ããªãšããŠã€ã³ããŒã
>>> ã¬ãžã¹ããª.PluginImporter()
>>> config = conf.ConfObject()
>>> volatility.commands ãã³ãã³ããšããŠã€ã³ããŒã
>>> volatility.addrspace ã addrspace ãšããŠã€ã³ããŒã
>>> registry.register_global_options(configãcommand.Command)
>>> registry.register_global_options(config, addrspace.BaseAddressSpace)
>>> config.parse_options()
>>> config.PROFILE="WinXPSP2x86"
>>> config.LOCATION = "file:///media/memory/private/image.dmp"
>>> volatility.plugins.taskmods ã taskmods ãšããŠã€ã³ããŒããã
>>> p = taskmods.PSList(config)
>>> p.calculate() ã®åŠç:
...å°å·ããã»ã¹
äŸ
å©çšå¯èœãªãã¹ãŠã®ãã©ã°ã€ã³ããããã¡ã€ã«ãã¹ãã£ã㌠ãã§ãã¯ãããã³ã¢ãã¬ã¹ ã¹ããŒã¹ã衚瀺ããã«ã¯ã次ã®æé ãå®è¡ããŸãã
$ ãã©ãã£ãªã㣠--æ å ±
MS Windows 8 SP0 ã§èŠã€ãã£ããã¹ãŠã®ã¢ã¯ãã£ããªããã»ã¹ãäžèŠ§è¡šç€ºããã«ã¯ ç»å:
$ volatility -f win8.raw --profile=Win8SP0x86 pslist
MS Windows 8 SP0 ã§èŠã€ãã£ããã¹ãŠã®ã¢ã¯ãã£ããªããã»ã¹ãäžèŠ§è¡šç€ºããã«ã¯ ç»åãã¿ã€ã ãŸãŒã³ã䜿çš:
$ volatility -f win8.raw --profile=Win8SP0x86 pslist --tz=ã¢ã¡ãªã«/ãµã³ããŠã
Linux 3.2.63 ããã«ãŒãã«ãããã¡ã衚瀺ããã«ã¯ ç»å:
$ volatility -f mem.dd --profile=Linux_3_2_63_x64 linux_dmesg
泚æäºé
ãã®ãã³ããŒãžã¯ããã©ãã£ãªãã£ã«é¢ããããã€ãã®ãã¹ããšããã€ãã®å ¬åŒææžã«åºã¥ããŠããŸãã ããã«
ãã®ä»ã®æ å ±ãšãã¥ãŒããªã¢ã«ã«ã€ããŠã¯ã以äžãåç §ããŠãã ããã
· http://www.volatilityfoundation.org
ã»https://github.com/volatilityfoundation/ä¹±é«äž/ wiki
onworks.net ãµãŒãã¹ã䜿çšããŠãªã³ã©ã€ã³ã§ãã©ãã£ãªãã£ã䜿çšãã