一款基于Volatility的开源内存分析工具,旨在为社区提供展示有趣新技术的试验场。这些技术试图通过数据精简和专家知识编码来加快调查过程。
NOTE: Most DAMM output looks better piped through 'less -S' (upper 'S') as in:
python damm.py -h usage: damm.py [-h] [-d DIR] [-p PLUGIN [PLUGIN ...]] [-f FILE] [-k KDBG] [--db DB] [--profile PROFILE] [--debug] [--info] [--tsv] [--grepable] [--filter FILTER] [--filtertype FILTERTYPE] [--diff BASELINE] [-u FIELD [FIELD ...]] [--warnings] [-q]
DAMM v1.0 Beta
optional arguments: -h, --help show this help message and exit -d DIR Path to additional plugin directory -p PLUGIN [PLUGIN ...] Plugin(s) to run. For a list of options use --info -f FILE Memory image file to run plugin on -k KDBG KDBG address for the images (in hex) --db DB SQLite db file, for efficient input/output --profile PROFILE Volatility profile for the images (e.g. WinXPSP2x86) --debug Print debugging statements --info Print available volatility profiles, plugins --tsv Print screen formatted output. --grepable Print in grepable text format --filter FILTER Filter results on name:value pair, e.g., pid:42 --filtertype FILTERTYPE Filter match type; either "exact" or "partial", defaults to partial --diff BASELINE Diff the imageFile|db with this db file as a baseline -u FIELD [FIELD ...] Use the specified fields to determine uniqueness of memobjs when diffing --warnings Look for suspicious objects. -q Query the supplied db (via --db).
### 支持的插件 <a name="plugins"/>
参见 #python damm.py --info
apihooks callbacks connections devicetree dlls evtlogs handles idt injections messagehooks mftentries modules mutants privileges processes services sids timers
### 示例 <a name="example"/>
提供一个类似于 Volatility 中的profile、内存镜像以及要运行的插件列表(或 'all')以获取终端输出:```
python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes | less -S
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes dlls modules)
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p all)
processes
offset name pid ppid prio image_path_name create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd command_line
0x25c8830 System 4 0 8 59 403 False True True True True False False False
0x225ada0 alg.exe 188 668 8 C:\WINDOWS\System32\alg.exe 2010-10-29 17:09:09 UTC+0000 6 0 107 False True True True True True True True C:\WINDOWS\System32\alg.exe
0x2114938 ipconfig.exe 304 968 8 2011-06-03 04:31:35 UTC+0000 2011-06-03 04:31:36 UTC+0000 0 0 False True True False True False False False
0x2086978 TSVNCache.exe 324 1196 8 C:\Program Files\TortoiseSVN\bin\TSVNCache.exe 2010-10-29 17:11:49 UTC+0000 7 0 54 False True True True True True True True "C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
0x22df020 smss.exe 376 4 11 \SystemRoot\System32\smss.exe 2010-10-29 17:08:53 UTC+0000 3 19 False True True True True False False False \SystemRoot\System32\smss.exe
...
要使这些结果持久化到SQLite数据库中,只需提供一个数据库文件名即可:``` python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes --db my_results.db
这将把结果打印到终端,同时将它们存储在 'my_results.db' 中。
要再次查看结果:```
python damm.py -p processes --db my_results.db
(请注意,您不再需要内存映像或指定配置文件,并且无论原始处理耗时多长,列表都会几乎瞬间生成。)
如果您稍后想要查看进程和其他插件:``` python damm.py --profile WinXPSP2x86 -p processes dlls modules --db my_results.db
Will:
1. 从数据库中查询 'processes' 输出
2. 运行 'dlls' 和 'modules' 插件
3. 显示结果
4. 将新结果存入数据库
一旦你在数据库中存储了一些数据,你可以使用 -q 开关进行查询。```
python damm.py -q --db my_results.db
profile: WinXPSP2x86
memimg: WinXPSP2x86/stuxnet.vmem
COMPUTERNAME: JAN-DF663B3DBF1
plugins: processes dlls modules
插件具有属性,这些属性可以具有用于筛选的类型,例如对于进程:(使用 --info 查看所有插件属性)``` offset name : string pid : pid ppid : pid image_path_name : string command_line : string create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd
这些属性和类型可以被DAMM的差异比较和过滤功能利用
### 差异比较 <a name="differencing"/>
要使用差异比较引擎,从两个不同的内存映像创建两个数据库,例如一个在恶意软件执行之前,一个在之后。```
python damm.py --profile WinXPSP2x86-f before.dmp -p processes --db before.db
python damm.py --profile WinXPSP2x86 -f after.dmp -p processes --db after.db
然后对基线数据库(此处为来自未感染内存映像的数据库)使用 --diff 选项。```
python damm.py -p processes --db after.db --diff before.db
processes Status offset name pid ppid prio image_path_name create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd command_line New 0x17d22e0 pythonw.exe 1256 1940 8 2013-10-31 23:23:14 UTC+0000 2013-10-31 23:23:19 UTC+0000 0 -268370093 False False True False False False False False Changed 0x18b4d38 svchost.exe 1080 692 8 2013-10-31 17:21:26 UTC+0000 66->71 False False True False False False False False Changed 0x1915198 winlogon.exe 648 376 13 2013-10-31 17:21:25 UTC+0000 24->26 False False True False False False False False Changed 0x1900120 services.exe 692 648 9 2013-10-31 17:21:25 UTC+0000 16->18 False False True False False False False False Changed 0x18b0360 svchost.exe 1124 692 8 2013-10-31 17:21:26 UTC+0000 5->6 False False True False False False False False Changed 0x1875490 explorer.exe 1636 1596 8 2013-10-31 17:21:27 UTC+0000 13->14 False False True False False False False False ...
结果看起来类似于上面的'processes'插件输出,但存在一些差异:
* 仅显示在'after.db'中新增的结果,或者同时存在于两个数据库中但某些属性相对于'before.db'发生了变化的结果(此处输出已截断)。
* 仅存在于'after.db'中的结果在第一列('Status')中显示'New'。
* 在两个数据库之间发生变化的结果的状态为'Changed',并且重要的是,用'->'标识DAMM检测到的变化:在上述输出的最后一行中,线程数量发生了变化。