Skip to content

Feature/process access - #2019

Open
beyzacoban wants to merge 4 commits into
volatilityfoundation:developfrom
beyzacoban:feature/process-access
Open

Feature/process access#2019
beyzacoban wants to merge 4 commits into
volatilityfoundation:developfrom
beyzacoban:feature/process-access

Conversation

@beyzacoban

Copy link
Copy Markdown

This PR adds a new Windows plugin, windows.processaccess.ProcessAccess, for analyzing process-to-process handles in Windows memory images.

The plugin builds on the existing windows.handles functionality and provides a process-centric view by resolving the handle owner, target process, and the access rights granted by each process handle.

The existing windows.handles plugin exposes GrantedAccess as a raw hexadecimal value. For memory forensic analysis, it can be useful to determine which specific process access rights are granted between two processes.

This plugin translates these masks into human-readable rights such as:

PROCESS_VM_READ
PROCESS_VM_WRITE
PROCESS_VM_OPERATION
PROCESS_CREATE_THREAD
PROCESS_DUP_HANDLE
PROCESS_SUSPEND_RESUME

This can help analysts investigate cross-process memory access and process manipulation while leaving interpretation of the findings to the analyst.

Unit tests are included for:

Access-mask decoding
Preservation of unknown access-mask bits
Empty access masks
Memory-related access filtering

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant