-
Notifications
You must be signed in to change notification settings - Fork 14
59 lines (52 loc) · 1.91 KB
/
check-tcpip.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
name: Check tcpip.sys
on:
schedule:
- cron: '0 7 * * *'
jobs:
check:
strategy:
matrix:
python: [3.9]
platform: [windows-2022, windows-2019]
runs-on: ${{ matrix.platform }}
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Clone volatility 3 & Create symbol file
run: |
pip3 install pefile==2022.5.30 yara-python capstone
$guid = (python3 guid-check-tcpip.py)
New-Item guid.txt -Value $guid
Write-Output "tcpip guid: $guid"
git clone https://github.com/volatilityfoundation/volatility3.git
cd volatility3
python3 setup.py install
python3 volatility3/framework/symbols/windows/pdbconv.py -p tcpip.pdb -g $guid
cd ..
try {
Move-Item volatility3/*.json.xz symbols/windows/tcpip.pdb/
} catch {
Write-Output "No change."
}
Remove-Item volatility3/* -Recurse
- name: Check tcpip version & Push symbol files
shell: powershell
run: |
$exePath = "C:\\Windows\\System32\\drivers\\tcpip.sys"
$vi = (Get-ItemProperty $exePath).VersionInfo
$fileVersion = ([string]$vi.FileMajorPart) + "." + ([string]$vi.FileMinorPart) + "." + ([string]$vi.FileBuildPart) + "." + ([string]$vi.FilePrivatePart)
Write-Output "tcpip version: $fileVersion"
$guid = (Get-Content guid.txt -Raw).ToLower()
Remove-Item guid.txt
git config --global user.email ${{ secrets.GH_MAIL }}
git config --global user.name ${{ secrets.GH_USER }}
$status = (git status -s)
if ($status.Length -eq 2) {
git pull
Write-Output "Added tcpip.pdb symbol file $fileVersion"
git add symbols/windows/tcpip.pdb/*
git commit -m "Added new tcpip.pdb symbol file $fileVersion"
git push origin main
} else {
Write-Output "No change."
}