HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
params.h
Go to the documentation of this file.
1#pragma once
2#include <sstream>
3#include <codecvt>
4#include <locale>
5
6#include <pe_sieve_types.h>
7#include <paramkit.h>
8
10#include "../term_util.h"
11
12using namespace paramkit;
13using namespace pesieve;
14
15#define HH_URL "https://github.com/hasherezade/hollows_hunter"
16
17//scan options:
18#define PARAM_IAT "iat"
19#define PARAM_HOOKS "hooks"
20#define PARAM_SHELLCODE "shellc"
21#define PARAM_OBFUSCATED "obfusc"
22#define PARAM_THREADS "threads"
23#define PARAM_DATA "data"
24#define PARAM_MODULES_IGNORE "mignore"
25#define PARAM_PROCESSES_IGNORE "pignore"
26#define PARAM_PNAME "pname"
27#define PARAM_PID "pid"
28#define PARAM_LOOP "loop"
29#define PARAM_ETW "etw"
30#define PARAM_REFLECTION "refl"
31#define PARAM_CACHE "cache"
32#define PARAM_DOTNET_POLICY "dnet"
33#define PARAM_SYMBOLS "sym"
34#define PARAM_PTIMES "ptimes"
35#define PARAM_ARCH "arch"
36
37//dump options:
38#define PARAM_IMP_REC "imp"
39#define PARAM_DUMP_MODE "dmode"
40#define PARAM_REBASE "rebase"
41
42//output options:
43#define PARAM_QUIET "quiet"
44#define PARAM_OUT_FILTER "ofilter"
45#define PARAM_RESULTS_FILTER "report"
46#define PARAM_SUSPEND "suspend"
47#define PARAM_KILL "kill"
48#define PARAM_UNIQUE_DIR "uniqd"
49#define PARAM_DIR "dir"
50#define PARAM_PATTERN "pattern"
51#define PARAM_MINIDUMP "minidmp"
52#define PARAM_LOG "log"
53#define PARAM_JSON "json"
54#define PARAM_JSON_LVL "jlvl"
55
56
57std::string version_to_str(DWORD version)
58{
59 BYTE *chunks = (BYTE*)&version;
60 std::stringstream stream;
61 stream << std::hex <<
62 (int)chunks[3] << "." <<
63 (int)chunks[2] << "." <<
64 (int)chunks[1] << "." <<
65 (int)chunks[0];
66
67 return stream.str();
68}
69
70void print_version(const std::string &version , WORD info_color = HILIGHTED_COLOR)
71{
72 WORD old_color = hh::util::set_color(info_color);
73 std::cout << "HollowsHunter v." << version;
74 DWORD pesieve_ver = PESieve_version;
75#ifdef _WIN64
76 std::cout << " (x64)" << "\n";
77#else
78 std::cout << " (x86)" << "\n";
79#endif
80 std::cout << "Built on: " << __DATE__ << "\n\n";
81 std::cout << "using: PE-sieve v." << version_to_str(pesieve_ver);
82 hh::util::set_color(old_color);
83 std::cout << std::endl;
84}
85
86std::wstring to_wstring(const std::string& stringToConvert)
87{
88 const std::wstring wideString = hh::util::utf8_to_wstring(stringToConvert);
89 return wideString;
90}
91
92std::string cache_mode_to_id(const t_cache_mode mode)
93{
94 switch (mode) {
95 case CACHE_DISABLED:
96 return "D";
97 case CACHE_AUTO:
98 return "A";
99 case CACHE_ENABLED:
100 return "E";
101 }
102 return "";
103}
104
105std::string translate_cache_mode(const t_cache_mode mode)
106{
107 switch (mode) {
108 case CACHE_DISABLED:
109 return "cache always disabled";
110 case CACHE_AUTO:
111 return "automatically enable cache in continuous scanning mode (default)";
112 case CACHE_ENABLED:
113 return "cache always enabled";
114 }
115 return "";
116}
117
118class HHParams : public Params
119{
120public:
121 HHParams(const std::string &version)
122 : Params(version)
123 {
124 {
125 std::stringstream ss1;
126 ss1 << "Scan only processes with given PIDs.";
127 std::stringstream ss2;
128 ss2 << INFO_SPACER << "Example: 5367" << PARAM_LIST_SEPARATOR << "0xa90";
129 this->addParam(new IntListParam(PARAM_PID, false, PARAM_LIST_SEPARATOR));
130 this->setInfo(PARAM_PID, ss1.str(), ss2.str());
131 }
132 {
133 std::stringstream ss1;
134 ss1 << "Scan only processes with given names.";
135 std::stringstream ss2;
136 ss2 << INFO_SPACER << "Example: iexplore.exe" << PARAM_LIST_SEPARATOR << "firefox.exe";
137 this->addParam(new StringListParam(PARAM_PNAME, false, PARAM_LIST_SEPARATOR));
138 this->setInfo(PARAM_PNAME, ss1.str(), ss2.str());
139 }
140 {
141 std::stringstream ss1;
142 ss1 << "Make a unique, timestamped directory for the output of each scan.";
143 std::stringstream ss2;
144 ss2 << INFO_SPACER << "Prevents overwriting results from previous scans.";
145 this->addParam(new BoolParam(PARAM_UNIQUE_DIR, false));
146 this->setInfo(PARAM_UNIQUE_DIR, ss1.str(), ss2.str());
147 }
148 {
149 std::stringstream ss1;
150 ss1 << "Do not scan process/es with given name/s.";
151 std::stringstream ss2;
152 ss2 << INFO_SPACER << "Example: explorer.exe" << PARAM_LIST_SEPARATOR << "conhost.exe";
153 this->addParam(new StringListParam(PARAM_PROCESSES_IGNORE, false, PARAM_LIST_SEPARATOR));
154 this->setInfo(PARAM_PROCESSES_IGNORE, ss1.str(), ss2.str());
155 }
156
157 this->addParam(new IntParam(PARAM_PTIMES, false, IntParam::INT_BASE_DEC));
158 this->setInfo(PARAM_PTIMES, "Skip processes created N or more seconds before the scanner start.");
159
160#ifdef _WIN64
161#endif
162
163 EnumParam* enumParam = new EnumParam(PARAM_ARCH, "process_arch", false);
164 if (enumParam) {
165 this->addParam(enumParam);
166 this->setInfo(PARAM_ARCH, "Scan only processes with given architecture.");
167 enumParam->addEnumValue(t_process_type::PROCESS_ALL, "All available");
168 enumParam->addEnumValue(t_process_type::PROCESS_32BIT, "Only 32-bit");
169 enumParam->addEnumValue(t_process_type::PROCESS_64BIT, "Only 64-bit");
170 }
171
172 this->addParam(new BoolParam(PARAM_SUSPEND, false));
173 this->setInfo(PARAM_SUSPEND, "Suspend processes detected as suspicious.");
174
175 this->addParam(new BoolParam(PARAM_LOG, false));
176 this->setInfo(PARAM_LOG, "Append each scan summary to the log.");
177
178 this->addParam(new BoolParam(PARAM_KILL, false));
179 this->setInfo(PARAM_KILL, "Kill processes detected as suspicious.");
180
181 this->addParam(new BoolParam(PARAM_HOOKS, false));
182 this->setInfo(PARAM_HOOKS, "Detect inline hooks and in-memory patches.");
183
184 this->addParam(new BoolParam(PARAM_LOOP, false));
185 this->setInfo(PARAM_LOOP, "Enable continuous scanning.");
186 BoolParam* etwParam = new BoolParam(PARAM_ETW, false);
187 if (etwParam) {
188 this->addParam(etwParam);
189 this->setInfo(PARAM_ETW, "Use ETW (requires Administrator privilege).");
190#ifndef USE_ETW
191 etwParam->setActive(false);
192 this->setInfo(PARAM_ETW, "Use ETW (disabled).");
193#endif //USE_ETW
194 }
195 enumParam = new EnumParam(PARAM_IMP_REC, "imprec_mode", false);
196 if (enumParam) {
197 this->addParam(enumParam);
198 this->setInfo(PARAM_IMP_REC, "Set in which mode the ImportTable should be recovered");
199 for (size_t i = 0; i < PE_IMPREC_MODES_COUNT; i++) {
200 t_imprec_mode mode = (t_imprec_mode)(i);
201 enumParam->addEnumValue(mode, imprec_mode_to_id(mode), translate_imprec_mode(mode));
202 }
203 }
204
205 enumParam = new EnumParam(PARAM_OUT_FILTER, "ofilter_id", false);
206 if (enumParam) {
207 this->addParam(enumParam);
208 this->setInfo(PARAM_OUT_FILTER, "Filter the dumped output.");
209 for (size_t i = 0; i < OUT_FILTERS_COUNT; i++) {
210 t_output_filter mode = (t_output_filter)(i);
211 enumParam->addEnumValue(mode, translate_out_filter(mode));
212 }
213 }
214
215 enumParam = new EnumParam(PARAM_RESULTS_FILTER, "result_type", false);
216 if (enumParam) {
217 this->addParam(enumParam);
218 this->setInfo(PARAM_RESULTS_FILTER, "Define what type of results are reported.");
219 for (DWORD i = SHOW_SUSPICIOUS; i <= SHOW_ALL; i++) {
220 t_results_filter mode = (t_results_filter)(i);
221 std::string info = translate_results_filter(mode);
222 if (info.empty()) continue;
223 enumParam->addEnumValue(mode, results_filter_to_id(i), info);
224 }
225 }
226
227 this->addParam(new StringListParam(PARAM_MODULES_IGNORE, false, PARAM_LIST_SEPARATOR));
228 {
229 std::stringstream ss1;
230 ss1 << "Do not scan module/s with given name/s.";
231 std::stringstream ss2;
232 ss2 << "\t Example: kernel32.dll" << PARAM_LIST_SEPARATOR << "user32.dll";
233 this->setInfo(PARAM_MODULES_IGNORE, ss1.str(), ss2.str());
234 }
235
236 this->addParam(new BoolParam(PARAM_QUIET, false));
237 this->setInfo(PARAM_QUIET, "Print only the summary. Do not log on stdout during the scan.");
238
239 this->addParam(new BoolParam(PARAM_JSON, false));
240 this->setInfo(PARAM_JSON, "Print the JSON report as the summary.");
241 //
242 //PARAM_JSON_LVL
243 enumParam = new EnumParam(PARAM_JSON_LVL, "json_lvl", false);
244 if (enumParam) {
245 this->addParam(enumParam);
246 this->setInfo(PARAM_JSON_LVL, "Level of details of the JSON report.");
247 for (size_t i = 0; i < JSON_LVL_COUNT; i++) {
248 t_json_level mode = (t_json_level)(i);
249 enumParam->addEnumValue(mode, translate_json_level(mode));
250 }
251 }
252
253 this->addParam(new BoolParam(PARAM_MINIDUMP, false));
254 this->setInfo(PARAM_MINIDUMP, "Create a minidump of the full suspicious process.");
255
256 //PARAM_DUMP_MODE
257 this->addParam(new BoolParam(PARAM_REBASE, false));
258 this->setInfo(PARAM_REBASE, "Rebase the module to its original base (if known).");
259
260 //PARAM_SHELLCODE
261 enumParam = new EnumParam(PARAM_SHELLCODE, "shellc_mode", false);
262 if (enumParam) {
263 this->addParam(enumParam);
264 this->setInfo(PARAM_SHELLCODE, "Detect shellcode implants (by patterns or statistics). ");
265 for (size_t i = 0; i < SHELLC_COUNT; i++) {
266 t_shellc_mode mode = (t_shellc_mode)(i);
267 enumParam->addEnumValue(mode, shellc_mode_mode_to_id(mode), translate_shellc_mode(mode));
268 }
269 }
270
271 //PARAM_OBFUSCATED
272 enumParam = new EnumParam(PARAM_OBFUSCATED, "obfusc_mode", false);
273 if (enumParam) {
274 this->addParam(enumParam);
275 this->setInfo(PARAM_OBFUSCATED, "Detect encrypted content, and possible obfuscated shellcodes.");
276 for (size_t i = 0; i < OBFUSC_COUNT; i++) {
277 t_obfusc_mode mode = (t_obfusc_mode)(i);
278 enumParam->addEnumValue(mode, obfusc_mode_mode_to_id(mode), translate_obfusc_mode(mode));
279 }
280 }
281
282 //PARAM_THREADS
283 this->addParam(new BoolParam(PARAM_THREADS, false));
284 this->setInfo(PARAM_THREADS, "Scan threads' callstack. Detect shellcodes, incl. 'sleeping beacons'.");
285
286 //PARAM_REFLECTION
287 this->addParam(new BoolParam(PARAM_REFLECTION, false));
288 this->setInfo(PARAM_REFLECTION, "Make a process reflection before scan.", "\t This allows i.e. to force-read inaccessible pages.");
289
290 //PARAM_CACHE
291 enumParam = new EnumParam(PARAM_CACHE, "cache_mode", false);
292 if (enumParam) {
293 this->addParam(enumParam);
294 this->setInfo(PARAM_CACHE, "Use modules caching. This can speed up the scan (on the cost of memory consumption).\n");
295 for (size_t i = 0; i < CACHE_MODES_COUNT; i++) {
296 t_cache_mode mode = (t_cache_mode)(i);
297 enumParam->addEnumValue(mode, cache_mode_to_id(mode), translate_cache_mode(mode));
298 }
299 }
300
301 //PARAM_IAT
302 enumParam = new EnumParam(PARAM_IAT, "iat_scan_mode", false);
303 if (enumParam) {
304 this->addParam(enumParam);
305 this->setInfo(PARAM_IAT, "Scan for IAT hooks.");
306 for (size_t i = 0; i < PE_IATS_MODES_COUNT; i++) {
307 t_iat_scan_mode mode = (t_iat_scan_mode)(i);
308 enumParam->addEnumValue(mode, translate_iat_scan_mode(mode));
309 }
310 }
311
312 this->addParam(new BoolParam(PARAM_SYMBOLS, false));
313 this->setInfo(PARAM_SYMBOLS, "Autodownload symbols for scanned modules.");
314
315 this->addParam(new StringParam(PARAM_PATTERN, false));
316 this->setInfo(PARAM_PATTERN, "Set additional shellcode patterns (file in the SIG format).");
317
318 //PARAM_DOTNET_POLICY
319 enumParam = new EnumParam(PARAM_DOTNET_POLICY, "dotnet_policy", false);
320 if (enumParam) {
321 this->addParam(enumParam);
322 this->setInfo(PARAM_DOTNET_POLICY, "Set the policy for scanning managed processes (.NET).");
323 for (size_t i = 0; i < PE_DNET_COUNT; i++) {
324 t_dotnet_policy mode = (t_dotnet_policy)(i);
325 enumParam->addEnumValue(mode, translate_dotnet_policy(mode));
326 }
327 }
328
329 //PARAM_DATA
330 enumParam = new EnumParam(PARAM_DATA, "data_scan_mode", false);
331 if (enumParam) {
332 this->addParam(enumParam);
333 this->setInfo(PARAM_DATA, "Set if non-executable pages should be scanned.");
334 for (size_t i = 0; i < PE_DATA_COUNT; i++) {
335 t_data_scan_mode mode = (t_data_scan_mode)(i);
336 enumParam->addEnumValue(mode, translate_data_mode(mode));
337 }
338 }
339
340 //PARAM_DUMP_MODE
341 enumParam = new EnumParam(PARAM_DUMP_MODE, "dump_mode", false);
342 if (enumParam) {
343 this->addParam(enumParam);
344 this->setInfo(PARAM_DUMP_MODE, "Set in which mode the detected PE files should be dumped.");
345 for (size_t i = 0; i < PE_DUMP_MODES_COUNT; i++) {
346 t_dump_mode mode = (t_dump_mode)(i);
347 enumParam->addEnumValue(mode, dump_mode_to_id(mode), translate_dump_mode(mode));
348 }
349 }
350 //PARAM_DIR
351 this->addParam(new StringParam(PARAM_DIR, false));
352 this->setInfo(PARAM_DIR, "Set a root directory for the output (default: \""+ std::string(HH_DEFAULT_DIR) + "\").");
353
354 //optional: group parameters
355 std::string str_group = "7. output options";
356 this->addGroup(new ParamGroup(str_group));
357 this->addParamToGroup(PARAM_DIR, str_group);
358 this->addParamToGroup(PARAM_JSON, str_group);
359 this->addParamToGroup(PARAM_JSON_LVL, str_group);
360 this->addParamToGroup(PARAM_OUT_FILTER, str_group);
361 this->addParamToGroup(PARAM_RESULTS_FILTER, str_group);
362 this->addParamToGroup(PARAM_LOG, str_group);
363 this->addParamToGroup(PARAM_UNIQUE_DIR, str_group);
364
365 str_group = "2. scanner settings";
366 this->addGroup(new ParamGroup(str_group));
367 this->addParamToGroup(PARAM_QUIET, str_group);
368 this->addParamToGroup(PARAM_REFLECTION, str_group);
369 this->addParamToGroup(PARAM_SYMBOLS, str_group);
370 this->addParamToGroup(PARAM_CACHE, str_group);
371 this->addParamToGroup(PARAM_LOOP, str_group);
372
373 str_group = "4. scan options";
374 this->addGroup(new ParamGroup(str_group));
375 this->addParamToGroup(PARAM_DATA, str_group);
376 this->addParamToGroup(PARAM_IAT, str_group);
377 this->addParamToGroup(PARAM_SHELLCODE, str_group);
378 this->addParamToGroup(PARAM_OBFUSCATED, str_group);
379 this->addParamToGroup(PARAM_THREADS, str_group);
380 this->addParamToGroup(PARAM_HOOKS, str_group);
381 this->addParamToGroup(PARAM_PATTERN, str_group);
382 this->addParamToGroup(PARAM_ETW, str_group);
383
384 str_group = "5. dump options";
385 this->addGroup(new ParamGroup(str_group));
386 this->addParamToGroup(PARAM_MINIDUMP, str_group);
387 this->addParamToGroup(PARAM_IMP_REC, str_group);
388 this->addParamToGroup(PARAM_DUMP_MODE, str_group);
389 this->addParamToGroup(PARAM_REBASE, str_group);
390
391 str_group = "3. scan exclusions";
392 this->addGroup(new ParamGroup(str_group));
393 this->addParamToGroup(PARAM_DOTNET_POLICY, str_group);
394 this->addParamToGroup(PARAM_MODULES_IGNORE, str_group);
395 this->addParamToGroup(PARAM_PROCESSES_IGNORE, str_group);
396
397 str_group = "1. scan targets";
398 this->addGroup(new ParamGroup(str_group));
399 this->addParamToGroup(PARAM_PID, str_group);
400 this->addParamToGroup(PARAM_PNAME, str_group);
401 this->addParamToGroup(PARAM_PTIMES, str_group);
402 this->addParamToGroup(PARAM_ARCH, str_group);
403
404 str_group = "6. post-scan actions";
405 this->addGroup(new ParamGroup(str_group));
406 this->addParamToGroup(PARAM_KILL, str_group);
407 this->addParamToGroup(PARAM_SUSPEND, str_group);
408 }
409
411 {
412 char logo2[] = ""
413 "@@@ @@@ @@@@@@ @@@ @@@ @@@@@@ @@@ @@@ @@@ @@@@@@\n"
414 "@@! @@@ @@! @@@ @@! @@! @@! @@@ @@! @@! @@! !@@ \n"
415 "@!@!@!@! @!@ !@! @!! @!! @!@ !@! @!! !!@ @!@ !@@!! \n"
416 "!!: !!! !!: !!! !!: !!: !!: !!! !: !!: !! !:!\n"
417 " : : : : :. : : ::.: : : ::.: : : :. : ::.: ::: ::.: : \n"
418 " @@@ @@@ @@@ @@@ @@@ @@@ @@@@@@@ @@@@@@@@ @@@@@@@ \n"
419 " @@! @@@ @@! @@@ @@!@!@@@ @!! @@! @@! @@@ \n"
420 " @!@!@!@! @!@ !@! @!@@!!@! @!! @!!!:! @!@!!@! \n"
421 " !!: !!! !!: !!! !!: !!! !!: !!: !!: :!! \n"
422 " : : : :.:: : :: : : : :: :: : : : \n";
423 char *logo = logo2;
424 WORD logo_color = DARK_MAGENTA;
425
426 WORD curr_color = 0;
427 if (hh::util::get_current_color(STD_OUTPUT_HANDLE, curr_color)) {
428 WORD current_bg = GET_BG_COLOR(curr_color);
429 if (current_bg == logo_color) {
430 logo_color = MAKE_COLOR(CYAN, current_bg);
431 }
432 }
433 WORD old_color = hh::util::set_color(logo_color);
434 std::cout << "\n" << logo << std::endl;
435 hh::util::set_color(old_color);
436 print_version(this->versionStr);
437 std::cout << std::endl;
438 std::cout << "Scans running processes. Recognizes and dumps a variety of in-memory implants:\nreplaced/implanted PEs, shellcodes, hooks, patches, etc.\n";
439 std::cout << "URL: " << HH_URL << std::endl;
440 }
441
443 {
445 bool hooks = false;
446 copyVal<BoolParam>(PARAM_HOOKS, hooks);
447 ps.pesieve_args.no_hooks = hooks ? false : true;
448
449 copyVal<EnumParam>(PARAM_CACHE, ps.cache_mode);
450 copyVal<BoolParam>(PARAM_UNIQUE_DIR, ps.unique_dir);
451 copyVal<BoolParam>(PARAM_SUSPEND, ps.suspend_suspicious);
452 copyVal<BoolParam>(PARAM_KILL, ps.kill_suspicious);
453 copyVal<EnumParam>(PARAM_ARCH, ps.process_arch);
454#ifdef USE_ETW
455 copyVal<BoolParam>(PARAM_ETW, ps.etw_scan);
456#endif // USE_ETW
457 copyVal<BoolParam>(PARAM_LOOP, ps.loop_scanning);
458 copyVal<BoolParam>(PARAM_LOG, ps.log);
459 copyVal<BoolParam>(PARAM_QUIET, ps.quiet);
460 copyVal<IntParam>(PARAM_PTIMES, ps.ptimes);
461 copyVal<BoolParam>(PARAM_JSON, ps.json_output);
462 copyVal<StringParam>(PARAM_DIR, ps.out_dir);
463
464 StringListParam* myParam = dynamic_cast<StringListParam*>(this->getParam(PARAM_PNAME));
465 if (myParam && myParam->isSet()) {
466 std::set<std::string> names_list;
467 myParam->stripToElements(names_list);
468 for (auto itr = names_list.begin(); itr != names_list.end(); itr++) {
469 ps.names_list.insert(to_wstring(*itr));
470 }
471 }
472
473 myParam = dynamic_cast<StringListParam*>(this->getParam(PARAM_PROCESSES_IGNORE));
474 if (myParam && myParam->isSet()) {
475 std::set<std::string> ignored_names_list;
476 myParam->stripToElements(ignored_names_list);
477 for (auto itr = ignored_names_list.begin(); itr != ignored_names_list.end(); itr++) {
478 ps.ignored_names_list.insert(to_wstring(*itr));
479 }
480 }
481 IntListParam* myIntParam = dynamic_cast<IntListParam*>(this->getParam(PARAM_PID));
482 if (myIntParam && myIntParam->isSet()) {
483 myIntParam->stripToIntElements(ps.pids_list);
484 }
485
486 ps.pesieve_args.use_cache = false;
487 if (ps.cache_mode == CACHE_ENABLED) {
488 ps.pesieve_args.use_cache = true;
489 }
490 else if (ps.cache_mode == CACHE_AUTO) {
491 if (ps.loop_scanning || ps.etw_scan) {
492 //continuous scanning: enable cache
493 ps.pesieve_args.use_cache = true;
494 }
495 }
496 }
497
499 {
500 free_strparam(ps.pesieve_args.modules_ignored);
501 free_strparam(ps.pesieve_args.pattern_file);
502 }
503
504protected:
505
506 // Fill PE-sieve params
507
508 bool alloc_strparam(PARAM_STRING& strparam, size_t len)
509 {
510 if (strparam.buffer != nullptr) { // already allocated
511 return false;
512 }
513 strparam.buffer = (char*)calloc(len + 1, sizeof(char));
514 if (strparam.buffer) {
515 strparam.length = len;
516 return true;
517 }
518 return false;
519 }
520
521 void free_strparam(pesieve::PARAM_STRING& strparam)
522 {
523 if (strparam.buffer) {
524 free(strparam.buffer);
525 }
526 strparam.buffer = nullptr;
527 strparam.length = 0;
528 }
529
530 bool fillStringParam(const std::string& paramId, PARAM_STRING& strparam)
531 {
532 StringParam* myStr = dynamic_cast<StringParam*>(this->getParam(paramId));
533 if (!myStr || !myStr->isSet()) {
534 return false;
535 }
536 std::string val = myStr->valToString();
537 const size_t len = val.length();
538 if (!len) {
539 return false;
540 }
541 alloc_strparam(strparam, len);
542 bool is_copied = false;
543 if (strparam.buffer) {
544 is_copied = copyCStr<StringParam>(paramId, strparam.buffer, strparam.length);
545 }
546 return is_copied;
547 }
548
549 void fillPEsieveStruct(t_params& ps)
550 {
551 copyVal<EnumParam>(PARAM_IMP_REC, ps.imprec_mode);
552 copyVal<EnumParam>(PARAM_OUT_FILTER, ps.out_filter);
553 copyVal<EnumParam>(PARAM_RESULTS_FILTER, ps.results_filter);
554
555 fillStringParam(PARAM_MODULES_IGNORE, ps.modules_ignored);
556
557 copyVal<BoolParam>(PARAM_REBASE, ps.rebase);
558 copyVal<BoolParam>(PARAM_QUIET, ps.quiet);
559 copyVal<EnumParam>(PARAM_JSON_LVL, ps.json_lvl);
560
561 copyVal<BoolParam>(PARAM_MINIDUMP, ps.minidump);
562 copyVal<EnumParam>(PARAM_SHELLCODE, ps.shellcode);
563 copyVal<EnumParam>(PARAM_OBFUSCATED, ps.obfuscated);
564 copyVal<BoolParam>(PARAM_THREADS, ps.threads);
565 copyVal<BoolParam>(PARAM_REFLECTION, ps.make_reflection);
566
567 copyVal<EnumParam>(PARAM_IAT, ps.iat);
568 copyVal<EnumParam>(PARAM_DOTNET_POLICY, ps.dotnet_policy);
569 copyVal<EnumParam>(PARAM_DATA, ps.data);
570 copyVal<EnumParam>(PARAM_DUMP_MODE, ps.dump_mode);
571
572 fillStringParam(PARAM_PATTERN, ps.pattern_file);
573
574 copyVal<BoolParam>(PARAM_SYMBOLS, ps.download_symbols);
575 }
576
577};
HHParams(const std::string &version)
Definition params.h:121
void free_strparam(pesieve::PARAM_STRING &strparam)
Definition params.h:521
bool fillStringParam(const std::string &paramId, PARAM_STRING &strparam)
Definition params.h:530
void freeStruct(t_hh_params &ps)
Definition params.h:498
bool alloc_strparam(PARAM_STRING &strparam, size_t len)
Definition params.h:508
void printBanner()
Definition params.h:410
void fillStruct(t_hh_params &ps)
Definition params.h:442
void fillPEsieveStruct(t_params &ps)
Definition params.h:549
struct hh_params t_hh_params
#define HH_DEFAULT_DIR
Definition hh_params.h:8
@ PROCESS_64BIT
Definition hh_params.h:21
@ PROCESS_32BIT
Definition hh_params.h:20
@ PROCESS_ALL
Definition hh_params.h:19
t_cache_mode
Definition hh_params.h:11
@ CACHE_AUTO
autodetect if cache should be enabled
Definition hh_params.h:13
@ CACHE_ENABLED
cache always enabled
Definition hh_params.h:14
@ CACHE_DISABLED
cache always disabled
Definition hh_params.h:12
@ CACHE_MODES_COUNT
Definition hh_params.h:15
bool get_current_color(int descriptor, WORD &color)
Definition term_util.cpp:12
std::wstring utf8_to_wstring(const std::string &utf8)
Definition term_util.cpp:83
WORD set_color(WORD color)
Definition term_util.cpp:21
#define PARAM_PROCESSES_IGNORE
Definition params.h:25
#define PARAM_CACHE
Definition params.h:31
#define PARAM_LOOP
Definition params.h:28
#define PARAM_IAT
Definition params.h:18
#define PARAM_RESULTS_FILTER
Definition params.h:45
#define PARAM_PATTERN
Definition params.h:50
std::string version_to_str(DWORD version)
Definition params.h:57
#define PARAM_PTIMES
Definition params.h:34
#define PARAM_ARCH
Definition params.h:35
#define PARAM_SYMBOLS
Definition params.h:33
#define PARAM_MINIDUMP
Definition params.h:51
std::string translate_cache_mode(const t_cache_mode mode)
Definition params.h:105
#define PARAM_IMP_REC
Definition params.h:38
#define PARAM_OUT_FILTER
Definition params.h:44
std::string cache_mode_to_id(const t_cache_mode mode)
Definition params.h:92
#define PARAM_OBFUSCATED
Definition params.h:21
#define PARAM_LOG
Definition params.h:52
#define PARAM_JSON
Definition params.h:53
#define PARAM_HOOKS
Definition params.h:19
#define PARAM_PID
Definition params.h:27
#define HH_URL
Definition params.h:15
#define PARAM_REBASE
Definition params.h:40
#define PARAM_DOTNET_POLICY
Definition params.h:32
#define PARAM_DATA
Definition params.h:23
#define PARAM_MODULES_IGNORE
Definition params.h:24
#define PARAM_UNIQUE_DIR
Definition params.h:48
std::wstring to_wstring(const std::string &stringToConvert)
Definition params.h:86
#define PARAM_QUIET
Definition params.h:43
#define PARAM_PNAME
Definition params.h:26
void print_version(const std::string &version, WORD info_color=HILIGHTED_COLOR)
Definition params.h:70
#define PARAM_THREADS
Definition params.h:22
#define PARAM_SUSPEND
Definition params.h:46
#define PARAM_SHELLCODE
Definition params.h:20
#define PARAM_JSON_LVL
Definition params.h:54
#define PARAM_DIR
Definition params.h:49
#define PARAM_ETW
Definition params.h:29
#define PARAM_DUMP_MODE
Definition params.h:39
#define PARAM_REFLECTION
Definition params.h:30
#define PARAM_KILL
Definition params.h:47
std::string translate_shellc_mode(const pesieve::t_shellc_mode &mode)
std::string translate_imprec_mode(const pesieve::t_imprec_mode imprec_mode)
std::string translate_out_filter(const pesieve::t_output_filter o_filter)
std::string translate_dump_mode(const DWORD dump_mode)
std::string obfusc_mode_mode_to_id(const pesieve::t_obfusc_mode &mode)
std::string translate_iat_scan_mode(const pesieve::t_iat_scan_mode mode)
std::string shellc_mode_mode_to_id(const pesieve::t_shellc_mode &mode)
std::string translate_data_mode(const pesieve::t_data_scan_mode &mode)
std::string translate_obfusc_mode(const pesieve::t_obfusc_mode &mode)
std::string translate_json_level(const pesieve::t_json_level &mode)
std::string translate_results_filter(const pesieve::t_results_filter r_filter)
std::string results_filter_to_id(const DWORD r_filter)
std::string translate_dotnet_policy(const pesieve::t_dotnet_policy &mode)
std::string imprec_mode_to_id(const pesieve::t_imprec_mode imprec_mode)
std::string dump_mode_to_id(const DWORD dump_mode)
std::set< long > pids_list
Definition hh_params.h:41
bool log
Definition hh_params.h:36
bool json_output
Definition hh_params.h:37
bool kill_suspicious
Definition hh_params.h:34
std::set< std::wstring > ignored_names_list
Definition hh_params.h:42
pesieve::t_params pesieve_args
Definition hh_params.h:44
std::string out_dir
Definition hh_params.h:29
bool etw_scan
Definition hh_params.h:32
bool quiet
Definition hh_params.h:35
t_process_type process_arch
Definition hh_params.h:43
std::set< std::wstring > names_list
Definition hh_params.h:40
t_cache_mode cache_mode
Definition hh_params.h:39
bool loop_scanning
Definition hh_params.h:31
bool suspend_suspicious
Definition hh_params.h:33
bool unique_dir
Definition hh_params.h:30
LONGLONG ptimes
Definition hh_params.h:38
#define MAKE_COLOR(fg_color, bg_color)
Definition term_util.h:27
#define DARK_MAGENTA
Definition term_util.h:15
#define CYAN
Definition term_util.h:21
#define GET_BG_COLOR(color)
Definition term_util.h:28