Skip to main content

Helper library to generate DRAKVUF profiles.

Project description

drakpdb

Helper library to generate DRAKVUF profiles.

Installation

pip3 install -r requirements.txt

Example

Generating profile from kernel (with LibVMI)

  1. Get PDB name and GUID/Age using vmi-win-guid

    # vmi-win-guid name windows7-sp1
    Windows Kernel found @ 0x2610000
            Version: 64-bit Windows 7
            PE GUID: 4ce7951a5ea000
            PDB GUID: 3844dbb920174967be7aa4a2c20430fa2
            Kernel filename: ntkrnlmp.pdb
            ...
    
  2. Download PDB and parse it to a json profile

    python3 drakpdb.py fetch_pdb ntkrnlmp.pdb 3844dbb920174967be7aa4a2c20430fa2
    python3 drakpdb.py parse_pdb ntkrnlmp.pdb > ntkrnlmp.json
    

Generating profile from DLL

  1. Use symchk.py from moyix/pdbparse to obtain PDB
  2. Use:
    python3 drakpdb.py parse_pdb dllname.pdb > dllname.json
    

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

drakpdb-0.2.2.tar.gz (49.6 kB view hashes)

Uploaded Source

Built Distributions

drakpdb-0.2.2-pp310-pypy310_pp73-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (66.9 kB view hashes)

Uploaded PyPy manylinux: glibc 2.17+ x86-64

drakpdb-0.2.2-pp39-pypy39_pp73-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (66.9 kB view hashes)

Uploaded PyPy manylinux: glibc 2.17+ x86-64

drakpdb-0.2.2-pp38-pypy38_pp73-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (66.9 kB view hashes)

Uploaded PyPy manylinux: glibc 2.17+ x86-64

drakpdb-0.2.2-cp312-cp312-musllinux_1_2_x86_64.whl (96.1 kB view hashes)

Uploaded CPython 3.12 musllinux: musl 1.2+ x86-64

drakpdb-0.2.2-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (95.9 kB view hashes)

Uploaded CPython 3.12 manylinux: glibc 2.17+ x86-64

drakpdb-0.2.2-cp311-cp311-musllinux_1_2_x86_64.whl (96.2 kB view hashes)

Uploaded CPython 3.11 musllinux: musl 1.2+ x86-64

drakpdb-0.2.2-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (96.0 kB view hashes)

Uploaded CPython 3.11 manylinux: glibc 2.17+ x86-64

drakpdb-0.2.2-cp310-cp310-musllinux_1_2_x86_64.whl (96.2 kB view hashes)

Uploaded CPython 3.10 musllinux: musl 1.2+ x86-64

drakpdb-0.2.2-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (95.9 kB view hashes)

Uploaded CPython 3.10 manylinux: glibc 2.17+ x86-64

drakpdb-0.2.2-cp39-cp39-musllinux_1_2_x86_64.whl (96.0 kB view hashes)

Uploaded CPython 3.9 musllinux: musl 1.2+ x86-64

drakpdb-0.2.2-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (95.8 kB view hashes)

Uploaded CPython 3.9 manylinux: glibc 2.17+ x86-64

drakpdb-0.2.2-cp38-cp38-musllinux_1_2_x86_64.whl (96.1 kB view hashes)

Uploaded CPython 3.8 musllinux: musl 1.2+ x86-64

drakpdb-0.2.2-cp38-cp38-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (96.3 kB view hashes)

Uploaded CPython 3.8 manylinux: glibc 2.17+ x86-64

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page