Skip to main content

OSWatcher Plugins

Analysis plugins for OSWatcher — extract and analyze operating system artifacts (filesystem, registry, PDB symbols, syscalls) and store them as a queryable graph in Neo4j.

Installation

pip install oswatcher-plugins

Plugins

Plugin Description
FileTypePlugin Identifies file types within OS filesystem snapshots
SymbolsPlugin Extracts PDB symbols and struct layouts from PE binaries
WinRegistryPlugin Parses and inserts Windows registry hives
SyscallsPlugin Extracts Windows/Linux syscall tables
LinuxSymbolsPlugin Extracts Linux kernel debug symbols

Usage

Plugins are run via the runner CLI against a single neogit commit:

runner <commit_hash> <plugin_name>
# example:
runner 930b7dc140b50b00c192a9ae7f97174823deb378 SYMBOLS

Available plugins: FILETYPE, SYMBOLS, WINREG, SYSCALLS, LINUX_SYMBOLS (the name is case-insensitive). Use runner --help for the full option list, including --force to rerun a plugin that has already been executed on the commit.

Requirements

  • Python 3.11+
  • A running Neo4j instance (configured via neogit settings)
  • neogit — the underlying graph storage library

Documentation

License

Apache 2.0 — see LICENSE.

Metadata

Release files for oswatcher-plugins 0.14.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for oswatcher-plugins 0.14.2
File Size Uploaded
oswatcher_plugins-0.14.2.tar.gz 30.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for oswatcher-plugins 0.14.2
File Interpreter ABI Platform
oswatcher_plugins-0.14.2-py3-none-any.whl Python 3 none any Details

Total release size: 70.1 kB

Release files / oswatcher_plugins-0.14.2.tar.gz

Download URL oswatcher_plugins-0.14.2.tar.gz
Size 30.5 kB
Tags Source
SHA-256 checksum
How to use checksums
663686e835e6e0fe4cc2b16652f1255849b6dfbd8db5ebc50b723385281774bb
BLAKE2b-256 checksum
How to use checksums
cc6b1aed817c75632aa02da569f824fb01d82988e2988b63b4adc88e749adfe2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.2.1 CPython/3.11.16 Linux/6.17.0-1022-azure

Release files / oswatcher_plugins-0.14.2-py3-none-any.whl

Download URL oswatcher_plugins-0.14.2-py3-none-any.whl
Size 39.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b2df7a0297ff0543b6c46a085a27cc652904ed0153a1bfbcdb88b1b0a79c49ab
BLAKE2b-256 checksum
How to use checksums
cf20c8692ffb6bcfdc76390f45cd28c70485047c285e3f4b96ac92da83e40abf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.2.1 CPython/3.11.16 Linux/6.17.0-1022-azure

Release history Release notifications | RSS feed

This release

0.14.2 This release

2 release files

0.14.1

2 release files

0.14.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page