Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 5 additions & 4 deletions cmd/fibratus/app/list/list.go
Original file line number Diff line number Diff line change
Expand Up @@ -21,15 +21,16 @@ package list
import (
"bufio"
"fmt"
"os"
"path/filepath"
"strings"

"github.com/jedib0t/go-pretty/v6/table"
"github.com/rabbitstack/fibratus/internal/bootstrap"
"github.com/rabbitstack/fibratus/pkg/config"
"github.com/rabbitstack/fibratus/pkg/event"
"github.com/rabbitstack/fibratus/pkg/filter/fields"
"github.com/spf13/cobra"
"os"
"path/filepath"
"strings"
)

var Command = &cobra.Command{
Expand Down Expand Up @@ -130,7 +131,7 @@ func listEvents(cmd *cobra.Command, args []string) {
t.AppendHeader(table.Row{"Name", "Category", "Description"})
t.SetStyle(table.StyleLight)

for _, ev := range event.GetTypesMeta() {
for _, ev := range event.GetTypesInfo() {
t.AppendRow(table.Row{ev.Name, ev.Category, ev.Description})
}

Expand Down
1 change: 0 additions & 1 deletion go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@ require (
github.com/Masterminds/sprig/v3 v3.2.2
github.com/Microsoft/go-winio v0.4.14
github.com/antchfx/htmlquery v1.2.5
github.com/bits-and-blooms/bitset v1.13.0
github.com/briandowns/spinner v1.12.0
github.com/cenkalti/backoff/v4 v4.3.0
github.com/dustin/go-humanize v1.0.0
Expand Down
2 changes: 0 additions & 2 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,6 @@ github.com/armon/consul-api v0.0.0-20180202201655-eb2c6b5be1b6/go.mod h1:grANhF5
github.com/aws/aws-sdk-go v1.34.13/go.mod h1:5zCpMtNQVjRREroY7sYe8lOMRSxkhG6MZveU8YkpAk0=
github.com/beorn7/perks v0.0.0-20180321164747-3a771d992973/go.mod h1:Dwedo/Wpr24TaqPxmxbtue+5NUziq4I4S80YR8gNf3Q=
github.com/beorn7/perks v1.0.0/go.mod h1:KWe93zE9D1o94FZ5RNwFwVgaQK1VOXiVxmqh+CedLV8=
github.com/bits-and-blooms/bitset v1.13.0 h1:bAQ9OPNFYbGHV6Nez0tmNI0RiEu7/hxlYJRUA0wFAVE=
github.com/bits-and-blooms/bitset v1.13.0/go.mod h1:7hO7Gc7Pp1vODcmWvKMRA9BNmbv6a/7QIWpPxHddWR8=
github.com/briandowns/spinner v1.12.0 h1:72O0PzqGJb6G3KgrcIOtL/JAGGZ5ptOMCn9cUHmqsmw=
github.com/briandowns/spinner v1.12.0/go.mod h1:QOuQk7x+EaDASo80FEXwlwiA+j/PPIcX3FScO+3/ZPQ=
github.com/cenkalti/backoff/v4 v4.3.0 h1:MyRJ/UdXutAwSAT+s3wNd7MfTIcy71VQueUuFK343L8=
Expand Down
8 changes: 4 additions & 4 deletions internal/etw/consumer.go
Original file line number Diff line number Diff line change
Expand Up @@ -78,8 +78,8 @@ func (c *Consumer) ProcessEvent(r *etw.EventRecord) error {
return nil
}

if !c.config.EventSource.EventExists(r.ID()) {
eventsUnknown.Add(1)
etype := event.NewTypeFromEventRecord(r)
if etype == event.Unknown {
return nil
}
if event.IsCurrentProcDropped(r.Header.ProcessID) && r.Header.ProviderID != etw.WindowsKernelProcessGUID {
Expand All @@ -92,13 +92,13 @@ func (c *Consumer) ProcessEvent(r *etw.EventRecord) error {
}
defer c.approvers.Cleanup(rec)

if c.config.EventSource.ExcludeEvent(rec.ID()) {
if c.config.EventSource.ExcludeEvent(etype) {
eventsExcluded.Add(1)
return nil
}

eventsProcessed.Add(1)
evt := event.New(c.sequencer.Get(), rec)
evt := event.New(c.sequencer.Get(), rec, etype)

// Dispatch each event to the processor chain.
// Processors may further augment the event with
Expand Down
12 changes: 7 additions & 5 deletions internal/etw/processors/fs_windows.go
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,7 @@ func newFsProcessor(
}

func (f *fsProcessor) ProcessEvent(e *event.Event) (*event.Event, bool, error) {
if e.Category == event.File {
if e.Category() == event.File {
evt, err := f.processEvent(e)
return evt, false, err
}
Expand Down Expand Up @@ -100,7 +100,7 @@ func (f *fsProcessor) processEvent(e *event.Event) (*event.Event, error) {
totalRundownFiles.Add(1)
f.files[fileObject] = &FileInfo{Name: filepath, Type: fs.GetFileType(filepath, 0)}
}
case event.MapFileRundown:
case event.MapViewOfSection:
fileKey := e.Params.MustGetUint64(params.FileKey)
fileinfo := f.files[fileKey]

Expand Down Expand Up @@ -144,7 +144,7 @@ func (f *fsProcessor) processEvent(e *event.Event) (*event.Event, error) {
// delete file metadata by file object address
fileObject := e.Params.MustGetUint64(params.FileObject)
delete(f.files, fileObject)
case event.UnmapViewFile:
case event.UnmapViewOfSection:
ok, proc := f.psnap.Find(e.PID)
addr := e.Params.TryGetAddress(params.FileViewBase)
if ok {
Expand All @@ -157,11 +157,13 @@ func (f *fsProcessor) processEvent(e *event.Event) (*event.Event, error) {
totalMapRundownFiles.Add(-1)

return e, f.psnap.RemoveMmap(e.PID, addr)
case event.FileOpEnd:
return e, nil
default:
var fileObject uint64
fileKey := e.Params.MustGetUint64(params.FileKey)

if !e.IsMapViewFile() {
if !e.IsMapViewOfSection() {
fileObject = e.Params.MustGetUint64(params.FileObject)
}

Expand Down Expand Up @@ -202,7 +204,7 @@ func (f *fsProcessor) processEvent(e *event.Event) (*event.Event, error) {
e.AppendParam(params.FilePath, params.Path, fileinfo.Name)
}

if e.IsMapViewFile() {
if e.IsMapViewOfSection() {
return e, f.psnap.AddMmap(e)
}
}
Expand Down
25 changes: 9 additions & 16 deletions internal/etw/processors/fs_windows_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -46,8 +46,7 @@ func TestFsProcessor(t *testing.T) {
{
"process file rundown",
&event.Event{
Type: event.FileRundown,
Category: event.File,
Type: event.FileRundown,
Params: event.Params{
params.FileObject: {Name: params.FileObject, Type: params.Uint64, Value: uint64(124567380264)},
params.FilePath: {Name: params.FilePath, Type: params.UnicodeString, Value: "C:\\Windows\\system32\\user32.dll"},
Expand All @@ -69,9 +68,8 @@ func TestFsProcessor(t *testing.T) {
{
"process mapped file rundown",
&event.Event{
PID: 10233,
Type: event.MapFileRundown,
Category: event.File,
PID: 10233,
Type: event.MapViewSectionRundown,
Params: event.Params{
params.FileKey: {Name: params.FileKey, Type: params.Uint64, Value: uint64(124567380264)},
params.FileViewSize: {Name: params.FileViewSize, Type: params.Uint64, Value: uint64(3098)},
Expand Down Expand Up @@ -99,8 +97,7 @@ func TestFsProcessor(t *testing.T) {
{
"release file and remove file info",
&event.Event{
Type: event.ReleaseFile,
Category: event.File,
Type: event.ReleaseFile,
Params: event.Params{
params.FileObject: {Name: params.FileObject, Type: params.Uint64, Value: uint64(18446738026482168384)},
params.FileKey: {Name: params.FileKey, Type: params.Uint64, Value: uint64(14446538026482168384)},
Expand All @@ -122,9 +119,8 @@ func TestFsProcessor(t *testing.T) {
{
"unmap view file",
&event.Event{
PID: 10233,
Type: event.UnmapViewFile,
Category: event.File,
PID: 10233,
Type: event.UnmapViewOfSection,
Params: event.Params{
params.FileKey: {Name: params.FileKey, Type: params.Uint64, Value: uint64(124567380264)},
params.FileViewSize: {Name: params.FileViewSize, Type: params.Uint64, Value: uint64(3098)},
Expand All @@ -147,8 +143,7 @@ func TestFsProcessor(t *testing.T) {
{
"process write file",
&event.Event{
Type: event.WriteFile,
Category: event.File,
Type: event.WriteFile,
Params: event.Params{
params.FileObject: {Name: params.FileObject, Type: params.Uint64, Value: uint64(18446738026482168384)},
params.FileKey: {Name: params.FileKey, Type: params.Uint64, Value: uint64(14446538026482168384)},
Expand All @@ -173,8 +168,7 @@ func TestFsProcessor(t *testing.T) {
{
"process write file consult handle snapshotter",
&event.Event{
Type: event.WriteFile,
Category: event.File,
Type: event.WriteFile,
Params: event.Params{
params.FileObject: {Name: params.FileObject, Type: params.Uint64, Value: uint64(18446738026482168384)},
params.FileKey: {Name: params.FileKey, Type: params.Uint64, Value: uint64(14446538026482168384)},
Expand All @@ -198,8 +192,7 @@ func TestFsProcessor(t *testing.T) {
{
"process enum directory",
&event.Event{
Type: event.EnumDirectory,
Category: event.File,
Type: event.EnumDirectory,
Params: event.Params{
params.FileObject: {Name: params.FileObject, Type: params.Uint64, Value: uint64(18446738026482168384)},
params.FileKey: {Name: params.FileKey, Type: params.Uint64, Value: uint64(14446538026482168384)},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ func (m memProcessor) Close() {
}

func (m memProcessor) ProcessEvent(e *event.Event) (*event.Event, bool, error) {
if e.Category == event.Mem {
if e.Category() == event.Memory {
pid := e.Params.MustGetPid()
if e.IsVirtualAlloc() {
// retrieve info about the range of pages and enrich the event
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@
package processors

import (
"os"
"testing"

"github.com/rabbitstack/fibratus/pkg/event"
"github.com/rabbitstack/fibratus/pkg/event/params"
"github.com/rabbitstack/fibratus/pkg/ps"
Expand All @@ -28,8 +31,6 @@ import (
"github.com/stretchr/testify/mock"
"github.com/stretchr/testify/require"
"golang.org/x/sys/windows"
"os"
"testing"
)

func TestMemProcessor(t *testing.T) {
Expand All @@ -47,8 +48,7 @@ func TestMemProcessor(t *testing.T) {
{
"virtual alloc",
&event.Event{
Type: event.VirtualAlloc,
Category: event.Mem,
Type: event.VirtualAlloc,
Params: event.Params{
params.MemRegionSize: {Name: params.MemRegionSize, Type: params.Uint64, Value: uint64(1024)},
params.MemBaseAddress: {Name: params.MemBaseAddress, Type: params.Address, Value: uint64(base)},
Expand All @@ -73,8 +73,7 @@ func TestMemProcessor(t *testing.T) {
{
"virtual free",
&event.Event{
Type: event.VirtualFree,
Category: event.Mem,
Type: event.VirtualFree,
Params: event.Params{
params.MemRegionSize: {Name: params.MemRegionSize, Type: params.Uint64, Value: uint64(1024)},
params.MemBaseAddress: {Name: params.MemBaseAddress, Type: params.Address, Value: uint64(base)},
Expand Down
10 changes: 1 addition & 9 deletions internal/etw/processors/net_windows.go
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,6 @@ package processors
import (
"github.com/rabbitstack/fibratus/pkg/event"
"github.com/rabbitstack/fibratus/pkg/event/params"
"github.com/rabbitstack/fibratus/pkg/network"
"github.com/rabbitstack/fibratus/pkg/util/ports"
)

Expand All @@ -38,14 +37,7 @@ func (netProcessor) Name() ProcessorType { return Net }
func (n netProcessor) Close() {}

func (n *netProcessor) ProcessEvent(e *event.Event) (*event.Event, bool, error) {
if e.Category == event.Net {
if e.IsNetworkTCP() && !e.IsDNS() {
e.AppendEnum(params.NetL4Proto, uint32(network.TCP), network.ProtoNames)
}
if e.IsNetworkUDP() && !e.IsDNS() {
e.AppendEnum(params.NetL4Proto, uint32(network.UDP), network.ProtoNames)
}

if e.Category() == event.Network {
if e.IsDNS() {
return e, false, nil
}
Expand Down
30 changes: 16 additions & 14 deletions internal/etw/processors/net_windows_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -19,12 +19,14 @@
package processors

import (
"net"
"testing"

"github.com/rabbitstack/fibratus/pkg/event"
"github.com/rabbitstack/fibratus/pkg/event/params"
"github.com/rabbitstack/fibratus/pkg/network"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"net"
"testing"
)

func TestNetworkProcessor(t *testing.T) {
Expand All @@ -36,13 +38,13 @@ func TestNetworkProcessor(t *testing.T) {
{
"send tcpv4",
&event.Event{
Type: event.SendTCPv4,
Category: event.Net,
Type: event.Send,
Params: event.Params{
params.NetDport: {Name: params.NetDport, Type: params.Uint16, Value: uint16(443)},
params.NetSport: {Name: params.NetSport, Type: params.Uint16, Value: uint16(43123)},
params.NetSIP: {Name: params.NetSIP, Type: params.IPv4, Value: net.ParseIP("127.0.0.1")},
params.NetDIP: {Name: params.NetDIP, Type: params.IPv4, Value: net.ParseIP("8.8.8.8")},
params.NetDport: {Name: params.NetDport, Type: params.Uint16, Value: uint16(443)},
params.NetSport: {Name: params.NetSport, Type: params.Uint16, Value: uint16(43123)},
params.NetSIP: {Name: params.NetSIP, Type: params.IPv4, Value: net.ParseIP("127.0.0.1")},
params.NetDIP: {Name: params.NetDIP, Type: params.IPv4, Value: net.ParseIP("8.8.8.8")},
params.NetL4Proto: {Name: params.NetL4Proto, Type: params.Enum, Value: uint32(network.TCP), Enum: network.ProtoNames},
},
},
func(e *event.Event, t *testing.T) {
Expand All @@ -58,13 +60,13 @@ func TestNetworkProcessor(t *testing.T) {
{
"recv udp6",
&event.Event{
Type: event.RecvUDPv6,
Category: event.Net,
Type: event.Recv,
Params: event.Params{
params.NetDport: {Name: params.NetDport, Type: params.Uint16, Value: uint16(53)},
params.NetSport: {Name: params.NetSport, Type: params.Uint16, Value: uint16(43123)},
params.NetSIP: {Name: params.NetSIP, Type: params.IPv4, Value: net.ParseIP("127.0.0.1")},
params.NetDIP: {Name: params.NetDIP, Type: params.IPv4, Value: net.ParseIP("8.8.8.8")},
params.NetDport: {Name: params.NetDport, Type: params.Uint16, Value: uint16(53)},
params.NetSport: {Name: params.NetSport, Type: params.Uint16, Value: uint16(43123)},
params.NetSIP: {Name: params.NetSIP, Type: params.IPv4, Value: net.ParseIP("127.0.0.1")},
params.NetDIP: {Name: params.NetDIP, Type: params.IPv4, Value: net.ParseIP("8.8.8.8")},
params.NetL4Proto: {Name: params.NetL4Proto, Type: params.Enum, Value: uint32(network.UDP), Enum: network.ProtoNames},
},
},
func(e *event.Event, t *testing.T) {
Expand Down
2 changes: 1 addition & 1 deletion internal/etw/processors/registry_windows.go
Original file line number Diff line number Diff line change
Expand Up @@ -102,7 +102,7 @@ func newRegistryProcessor(hsnap handle.Snapshotter) Processor {
}

func (r *registryProcessor) ProcessEvent(e *event.Event) (*event.Event, bool, error) {
if e.Category == event.Registry {
if e.Category() == event.Registry {
evt, err := r.processEvent(e)
return evt, false, err
}
Expand Down
Loading
Loading