-
Notifications
You must be signed in to change notification settings - Fork 62
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
addc7d8
commit fcc36d8
Showing
3 changed files
with
133 additions
and
17 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,72 @@ | ||
#!/usr/bin/env python3 | ||
# -*- coding: utf-8 -*- | ||
""" | ||
Windows-specific module to determine whether the current Python process is running in a PowerShell process. | ||
""" | ||
from __future__ import annotations | ||
|
||
import ctypes | ||
import functools | ||
import os | ||
|
||
from typing import Iterable, get_type_hints | ||
|
||
|
||
class FieldsFromTypeHints(type(ctypes.Structure)): | ||
def __new__(cls, name, bases, namespace): | ||
class AnnotationDummy: | ||
__annotations__ = namespace.get('__annotations__', {}) | ||
annotations = get_type_hints(AnnotationDummy) | ||
namespace['_fields_'] = list(annotations.items()) | ||
return type(ctypes.Structure).__new__(cls, name, bases, namespace) | ||
|
||
|
||
class PROCESSENTRY32(ctypes.Structure, metaclass=FieldsFromTypeHints): | ||
dwSize : ctypes.c_uint32 | ||
cntUsage : ctypes.c_uint32 | ||
th32ProcessID : ctypes.c_uint32 | ||
th32DefaultHeapID : ctypes.POINTER(ctypes.c_ulong) | ||
th32ModuleID : ctypes.c_uint32 | ||
cntThreads : ctypes.c_uint32 | ||
th32ParentProcessID : ctypes.c_uint32 | ||
pcPriClassBase : ctypes.c_long | ||
dwFlags : ctypes.c_uint32 | ||
szExeFile : ctypes.c_char * 260 | ||
|
||
|
||
def get_parent_processes() -> Iterable[str]: | ||
k32 = ctypes.windll.kernel32 | ||
entry = PROCESSENTRY32() | ||
entry.dwSize = ctypes.sizeof(PROCESSENTRY32) | ||
snap = k32.CreateToolhelp32Snapshot(2, 0) | ||
if not snap: | ||
raise RuntimeError('could not create snapshot') | ||
try: | ||
if not k32.Process32First(snap, ctypes.byref(entry)): | ||
raise RuntimeError('could not iterate processes') | ||
processes = { | ||
entry.th32ProcessID: ( | ||
entry.th32ParentProcessID, | ||
bytes(entry.szExeFile).decode('latin1') | ||
) for _ in iter( | ||
functools.partial(k32.Process32Next, snap, ctypes.byref(entry)), 0) | ||
} | ||
finally: | ||
k32.CloseHandle(snap) | ||
pid = os.getpid() | ||
while pid in processes: | ||
pid, path = processes[pid] | ||
yield path | ||
|
||
|
||
def is_powershell_process() -> bool: | ||
if os.name != 'nt': | ||
return False | ||
for process in get_parent_processes(): | ||
name, _ = os.path.splitext(process) | ||
name = name.lower() | ||
if name == 'cmd': | ||
return False | ||
if name == 'powershell': | ||
return True | ||
return False |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
#!/usr/bin/env python3 | ||
# -*- coding: utf-8 -*- | ||
from refinery.lib.powershell import get_parent_processes, is_powershell_process | ||
|
||
from .. import TestBase | ||
|
||
|
||
class TestPowerShellDetection(TestBase): | ||
|
||
def test_process_trace(self): | ||
processes = list(get_parent_processes()) | ||
self.assertTrue(any('python' in p for p in processes)) | ||
|
||
def test_not_running_in_powershell(self): | ||
self.assertFalse(is_powershell_process()) |