momo5502
43ff531354
Add NtRemoveIoCompletionEx syscall stub
2025-06-14 08:46:27 +02:00
Maurice Heumann
b76f5ab92d
minidump support: dump loading and process reconstruction ( #361 )
2025-06-14 08:21:00 +02:00
redthing1
1e63fe381f
minidump: tidy const refs
2025-06-12 15:25:37 -07:00
redthing1
afd80aa9af
make minidump loader fully standalone
2025-06-12 15:13:45 -07:00
redthing1
01d2656189
minidump loader: handle zero protection
2025-06-12 15:08:07 -07:00
redthing1
f8b163f556
refactor to address comments
2025-06-12 15:04:54 -07:00
3fault
e5e5d05d05
Add temp environment variables to fix GetTempPath(2)W
2025-06-10 09:59:34 -04:00
redthing1
21a0d3c4bc
fix tidy
2025-06-10 01:08:45 -07:00
redthing1
ca214a539a
minidump: more clang tidy
2025-06-10 00:57:19 -07:00
redthing1
47f4589774
minidump: satisfy clang tidy
2025-06-10 00:47:01 -07:00
redthing1
3fa9fa9c15
minidump: fix uintmax_t format specifier
2025-06-10 00:35:52 -07:00
redthing1
dae4f07f70
module manager: apply clang format
2025-06-10 00:31:17 -07:00
redthing1
aa966826a2
fixup! minidump loader: fix PRIx64 format specifier
2025-06-10 00:28:43 -07:00
redthing1
12646566ca
minidump loader: fix PRIx64 format specifier
2025-06-10 00:27:13 -07:00
redthing1
5d9dd122d2
minidump support: dump loading and process reconstruction
2025-06-09 23:12:45 -07:00
momo5502
906cec808a
Small fixes
2025-06-07 20:10:36 +02:00
Maurice Heumann
50e4a2e208
Update analysis.cpp
2025-06-07 15:04:45 +02:00
momo5502
f3b20da9cc
Optimize thread scheduling and pausing
2025-06-07 14:20:19 +02:00
momo5502
e26ac99551
Fix char16_t tolower conversion
2025-06-07 11:45:43 +02:00
momo5502
05c5f0a085
Final cleanup
2025-06-07 08:01:02 +02:00
momo5502
da4a4f90c9
Cleanup exception callbacks
2025-06-07 07:54:11 +02:00
momo5502
802e295bcc
Adapt more printing
2025-06-07 07:29:30 +02:00
momo5502
9372e27453
Fix module logging
2025-06-07 07:11:27 +02:00
momo5502
bc77faec3d
Move more logging into callbacks
2025-06-06 20:03:53 +02:00
momo5502
24939583c4
Fix serialization
2025-06-06 16:59:45 +02:00
momo5502
9b8ea27a29
Delay process setup
2025-06-05 20:53:38 +02:00
momo5502
f4282f44d7
Fix compilation
2025-06-05 19:20:45 +02:00
momo5502
3cfb29c5c1
Print buffered stdout
2025-06-05 19:06:39 +02:00
momo5502
f2e0e91630
Isolate more analysis into analyzer
2025-06-05 18:59:27 +02:00
momo5502
f046246740
Extract more analysis logic
2025-06-04 21:21:48 +02:00
momo5502
956e73d839
Some fixes
2025-06-04 20:47:51 +02:00
momo5502
d18a60561c
Fix warning
2025-06-04 20:26:33 +02:00
momo5502
1f829463c1
Use more semantic logging
2025-06-04 20:22:28 +02:00
momo5502
de0d9a17a5
Small fixes
2025-06-04 20:19:47 +02:00
momo5502
84e8e86b94
Extract sus activity logging
2025-06-04 19:28:50 +02:00
momo5502
5609de9dde
Small fixes and prepare for more semantic logging
2025-06-04 19:17:09 +02:00
momo5502
5230909c23
Switch back to using callbacks
2025-06-04 19:11:16 +02:00
momo5502
25295707ec
Event manager progress
2025-06-04 18:52:59 +02:00
momo5502
32fcbf3ded
Prepare event manager
...
The event manager forms the basis for semantic logging.
The emulator transmits events and the manager can handle them.
This means to either print information to stdout, do nothing, etc...
2025-06-03 20:30:12 +02:00
Maurice Heumann
dcee2982ce
Update file.cpp
2025-06-03 11:18:10 +02:00
Maurice Heumann
368a9dbdd1
Update file_management.hpp
2025-06-03 11:17:50 +02:00
Igor Pissolati
4fecea3aff
Apply review suggested change
2025-06-02 14:34:12 -03:00
Igor Pissolati
9f32620220
Fix failing checks
2025-06-02 14:32:15 -03:00
Igor Pissolati
c67146ee45
Add new syscalls
2025-06-02 14:32:15 -03:00
Igor Pissolati
db1588623b
Add KSecDD device and support for devices in NtQueryObject
2025-06-02 14:32:15 -03:00
Igor Pissolati
cc2266d934
Add new pseudo-handles
2025-06-02 14:32:15 -03:00
Igor Pissolati
ad3046466e
Improvements to NtQueryInformationToken
2025-06-02 14:32:15 -03:00
momo5502
9b2653afc4
Override timestamp counter for deterministic clock
2025-06-02 19:28:24 +02:00
Igor Pissolati
c47a498fe4
Add get_address, event_select and enum_network_events to afd_endpoint
2025-06-02 12:39:42 -03:00
momo5502
aa763c8392
Prepare more timer syscalls
2025-06-01 14:05:18 +02:00