:py:mod:`dissect.target.plugins.apps.av.sophos` =============================================== .. py:module:: dissect.target.plugins.apps.av.sophos Module Contents --------------- Classes ~~~~~~~ .. autoapisummary:: dissect.target.plugins.apps.av.sophos.SophosPlugin Attributes ~~~~~~~~~~ .. autoapisummary:: dissect.target.plugins.apps.av.sophos.HitmanAlertRecord dissect.target.plugins.apps.av.sophos.SophosLogRecord .. py:data:: HitmanAlertRecord .. py:data:: SophosLogRecord .. py:class:: SophosPlugin(target: dissect.target.Target) Bases: :py:obj:`dissect.target.plugin.Plugin` Base class for plugins. Plugins can optionally be namespaced by specifying the ``__namespace__`` class attribute. Namespacing results in your plugin needing to be prefixed with this namespace when being called. For example, if your plugin has specified ``test`` as namespace and a function called ``example``, you must call your plugin with ``test.example``:: A ``Plugin`` class has the following private class attributes: - ``__namespace__`` - ``__record_descriptors__`` With the following three being assigned in :func:`register`: - ``__plugin__`` - ``__functions__`` - ``__exports__`` Additionally, the methods and attributes of :class:`Plugin` receive more private attributes by using decorators. The :func:`export` decorator adds the following private attributes - ``__exported__`` - ``__output__``: Set with the :func:`export` decorator. - ``__record__``: Set with the :func:`export` decorator. The :func:`internal` decorator and :class:`InternalPlugin` set the ``__internal__`` attribute. Finally. :func:`args` decorator sets the ``__args__`` attribute. :param target: The :class:`~dissect.target.target.Target` object to load the plugin for. .. py:attribute:: __namespace__ :value: 'sophos' .. py:attribute:: LOG_SOPHOS_HOME :value: 'sysvol/ProgramData/Sophos/Clean/Logs/Clean.log' .. py:attribute:: LOG_SOPHOS_HITMAN :value: 'sysvol/ProgramData/HitmanPro.Alert/excalibur.db' .. py:attribute:: MARKER_INFECTION :value: '{"command":"clean-threat' .. py:attribute:: LOGS .. py:method:: check_compatible() -> None Perform a compatibility check with the target. This function should return ``None`` if the plugin is compatible with the current target (``self.target``). For example, check if a certain file exists. Otherwise it should raise an ``UnsupportedPluginError``. :raises UnsupportedPluginError: If the plugin could not be loaded. .. py:method:: hitmanlogs() -> Iterator[HitmanAlertRecord] Return alert log records from Sophos Hitman Pro/Alert. Yields HitmanAlertRecord with the following fields: ts (datetime): Timestamp. alert (string): Type of Alert. description (string): Short description of the alert. details (string): Detailed description of the alert. Note that because Hitman also catches suspicious behaviour of systems, the details field might contain a lot of text, it might contain stracktraces etc. .. py:method:: sophoshomelogs() -> Iterator[SophosLogRecord] Return log history records from Sophos Home. Yields SophosLogRecord with the following fields: ts (datetime): Timestamp. description (string): Short description of the alert. path (path): Path to the infected file (if available).