Skip to main content

pyscrings

Python bindings for scrings powered by PyO3 and maturin

scrings is a strings utility that will output only semantically valid strings based on tree-sitter grammar. For each script language we made a list of semantic nodes discriminant enough to detect the target language.

The main purpose is to support volatility.

Install

pyscrings is available on PyPi:

pip install pyscrings

Usage

pyscrings is using FileObject interface and will output a generator.

from pyscrings import powershell, javascript, php, bash, python, sql

with open("path_to_dump", "rb") as f:
    for (offset, match) in powershell(f):
        print((offset, repr(match)))

Another example using a BytesIO buffer :

import pyscrings, io
list(pyscrings.sql(io.BytesIO(b"********* select * from table *************"), 4))

[(10, 'select * from table')]

Docs

Powershell

def powershell(buffer : BinaryIO, step: Optional[int]) -> Generator[(int, str)]:
    '''
    Powershell strings with semantic validation
    
    :param buffer: input buffer to parse
    :param step: strings step use to find printable strings (default = 20)
    :returns: genrator of offset, valid powershell strings
    '''

Sql

def sql(buffer : BinaryIO, step: Optional[int]) -> Generator[(int, str)]:
    '''
    SQL strings with semantic validation
    
    :param buffer: input buffer to parse
    :param step: strings step use to find printable strings (default = 20)
    :returns: genrator of offset, valid sql strings
    '''

Javascript

def javascript(buffer : BinaryIO, step: Optional[int]) -> Generator[(int, str)]:
    '''
    Javascript strings with semantic validation
    
    :param buffer: input buffer to parse
    :param step: strings step use to find printable strings (default = 20)
    :returns: genrator of offset, valid javascript strings
    '''

Bash

def bash(buffer : BinaryIO, step: Optional[int]) -> Generator[(int, str)]:
    '''
    Bash strings with semantic validation
    
    :param buffer: input buffer to parse
    :param step: strings step use to find printable strings (default = 20)
    :returns: genrator of offset, valid bash strings
    '''

PHP

def php(buffer : BinaryIO, step: Optional[int]) -> Generator[(int, str)]:
    '''
    PHP strings with semantic validation
    
    :param buffer: input buffer to parse
    :param step: strings step use to find printable strings (default = 20)
    :returns: genrator of offset, valid php strings
    '''

Python

def python(buffer : BinaryIO, step: Optional[int]) -> Generator[(int, str)]:
    '''
    Python strings with semantic validation
    
    :param buffer: input buffer to parse
    :param step: strings step use to find printable strings (default = 20)
    :returns: genrator of offset, valid python strings
    '''

Build

pyscrings is powered by maturin

git clone https://github.com/airbus-cert/scrings
cd scrings\pyscrings

pip install maturin
maturin build --profile release

pip install target\wheels\*.whl

Metadata

Release files for pyscrings 0.1.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for pyscrings 0.1.6
File Interpreter ABI Platform
pyscrings-0.1.6-cp38-abi3-win_amd64.whl CPython 3.8 abi3 Windows x86-64 Details
pyscrings-0.1.6-cp38-abi3-manylinux_2_34_x86_64.whl CPython 3.8 abi3 Linux glibc 2.34+ x86-64 Details

Total release size: 2.2 MB

Release files / pyscrings-0.1.6-cp38-abi3-win_amd64.whl

Download URL pyscrings-0.1.6-cp38-abi3-win_amd64.whl
Size 998.1 kB
Tags CPython 3.8 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
af5fc2992c95ba3ae379cfef1cd60bc626fd12a5e0eeb6fa480d0cd2d9506d3a
BLAKE2b-256 checksum
How to use checksums
45c672ba21c6907ef1efa9789075a1ef816e281b589d3738067ef32d591d5265
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.0.1 CPython/3.10.5

Release files / pyscrings-0.1.6-cp38-abi3-manylinux_2_34_x86_64.whl

Download URL pyscrings-0.1.6-cp38-abi3-manylinux_2_34_x86_64.whl
Size 1.2 MB
Tags CPython 3.8 Linux glibc 2.34+ x86-64 abi3
SHA-256 checksum
How to use checksums
76a5ba66d69d0e8056215c9749c6e4098b882f256d0b8d26bd9f09c82d1197d1
BLAKE2b-256 checksum
How to use checksums
fbf566a99495f087b16e739ff87d0af4e927bb33d81c0c40f2b79b250ec3cb0b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.11.2

Release history Release notifications | RSS feed

This release

0.1.6 This release

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page