momo5502
|
5ebf2dfd81
|
Support skipping syscall logging
|
2025-12-22 16:13:58 +01:00 |
|
momo5502
|
90343077da
|
Fix ordinals
|
2025-12-22 14:02:15 +01:00 |
|
momo5502
|
69ddd7a93b
|
Small fixes
|
2025-12-22 07:42:34 +01:00 |
|
momo5502
|
cfebd2f35f
|
Fix WinVerifyTrust
|
2025-12-21 20:37:42 +01:00 |
|
brian
|
65eecf1cfd
|
Comprehensive WOW64 subsystem implementation
|
2025-10-13 19:55:50 +08:00 |
|
Maurice Heumann
|
afdae4aa8e
|
Update analysis.cpp
|
2025-09-25 07:31:22 +02:00 |
|
momo5502
|
6c5ca91b96
|
Shorter import logging
|
2025-09-21 16:45:24 +02:00 |
|
momo5502
|
3a55236fdf
|
Dump LoadLibraryA argument
|
2025-09-13 10:31:19 +02:00 |
|
momo5502
|
7b3e7ed07d
|
Tie import tracking to execution again
|
2025-09-08 20:14:49 +02:00 |
|
momo5502
|
e55e078e92
|
Simplify import watching
|
2025-09-08 19:12:33 +02:00 |
|
momo5502
|
a671deb383
|
Rename is_within method to contains
|
2025-09-08 18:40:25 +02:00 |
|
momo5502
|
dad460411c
|
Reduce cpuid, rdtsc and rdtscp logs in concise mode
|
2025-09-07 17:22:07 +02:00 |
|
Maurice Heumann
|
37310a308b
|
Fix Node.js analyzer
|
2025-08-24 08:43:23 +02:00 |
|
momo5502
|
80c8b88d23
|
Optimize instruction summary
|
2025-08-18 19:29:25 +02:00 |
|
momo5502
|
c71c204583
|
Print instruction summary
|
2025-08-18 19:16:56 +02:00 |
|
momo5502
|
c75f30fdfb
|
Optimize instruction bytes
|
2025-08-18 19:01:09 +02:00 |
|
momo5502
|
9ca18dd141
|
Fix linter warning
|
2025-08-17 07:52:45 +02:00 |
|
momo5502
|
584b770def
|
Store previous IP per thread
|
2025-08-17 07:32:26 +02:00 |
|
momo5502
|
9c29f26647
|
Small fixes
|
2025-08-17 07:26:11 +02:00 |
|
momo5502
|
7d6648ade0
|
Extend clang-format column limit to 140
|
2025-08-16 14:55:07 +02:00 |
|
momo5502
|
f3de9697d6
|
Prevent fallthrough to foreign transition if ignored
|
2025-08-16 14:27:11 +02:00 |
|
momo5502
|
ee2835d658
|
Enable instruction details
|
2025-08-16 13:48:52 +02:00 |
|
momo5502
|
397db6decc
|
Fix print
|
2025-08-16 11:53:44 +02:00 |
|
momo5502
|
3b72ae9709
|
Add capstone disassembler
|
2025-08-16 11:53:40 +02:00 |
|
momo5502
|
f12fd47d1d
|
Log transitions to foreign code
|
2025-08-15 15:30:08 +02:00 |
|
momo5502
|
127ed1b552
|
Log rdtsc
|
2025-08-15 12:54:36 +02:00 |
|
momo5502
|
3189e6f701
|
Log more interesting things if outside any mapped module
|
2025-08-13 19:50:04 +02:00 |
|
momo5502
|
982d02b674
|
Log invocations outside of any module
|
2025-08-13 19:09:44 +02:00 |
|
momo5502
|
a33e252e40
|
Kill WinVerifyTrust
|
2025-08-13 19:06:18 +02:00 |
|
momo5502
|
f9cee1837c
|
Print compare input
|
2025-08-10 12:43:35 +02:00 |
|
momo5502
|
94687d73fe
|
Small fixes
|
2025-08-10 11:18:05 +02:00 |
|
momo5502
|
5fbf065937
|
Handle debug strings via callback
|
2025-08-10 10:03:12 +02:00 |
|
momo5502
|
806aa8b61b
|
Print module name
|
2025-08-09 21:56:25 +02:00 |
|
momo5502
|
3b9320fd62
|
Better import access tracking
|
2025-08-09 18:02:37 +02:00 |
|
momo5502
|
eb6d352a81
|
Track import access
|
2025-08-09 17:07:33 +02:00 |
|
momo5502
|
acb65dc10d
|
Log message box arguments
|
2025-07-09 21:17:32 +02:00 |
|
Maurice Heumann
|
965efadb51
|
Detailed CPUID logging
|
2025-07-08 18:50:40 +02:00 |
|
Maurice Heumann
|
a9c30bce33
|
Also log ExpandEnvironmentStringsA
|
2025-07-08 12:29:20 +02:00 |
|
Maurice Heumann
|
43bcac8f5b
|
Print details for certain functions
|
2025-07-07 21:18:49 +02:00 |
|
Maurice Heumann
|
50e4a2e208
|
Update analysis.cpp
|
2025-06-07 15:04:45 +02:00 |
|
momo5502
|
f3b20da9cc
|
Optimize thread scheduling and pausing
|
2025-06-07 14:20:19 +02:00 |
|
momo5502
|
05c5f0a085
|
Final cleanup
|
2025-06-07 08:01:02 +02:00 |
|
momo5502
|
da4a4f90c9
|
Cleanup exception callbacks
|
2025-06-07 07:54:11 +02:00 |
|
momo5502
|
802e295bcc
|
Adapt more printing
|
2025-06-07 07:29:30 +02:00 |
|
momo5502
|
9372e27453
|
Fix module logging
|
2025-06-07 07:11:27 +02:00 |
|
momo5502
|
bc77faec3d
|
Move more logging into callbacks
|
2025-06-06 20:03:53 +02:00 |
|
momo5502
|
f4282f44d7
|
Fix compilation
|
2025-06-05 19:20:45 +02:00 |
|
momo5502
|
f2e0e91630
|
Isolate more analysis into analyzer
|
2025-06-05 18:59:27 +02:00 |
|
momo5502
|
f046246740
|
Extract more analysis logic
|
2025-06-04 21:21:48 +02:00 |
|
momo5502
|
956e73d839
|
Some fixes
|
2025-06-04 20:47:51 +02:00 |
|