This repository has been archived by the owner on Nov 17, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 23
Break on new a process entrypoint address #13
Labels
Comments
The value of Win32StartAddress is correct. |
Solution 1: watch the page tables until the missing page is inserted:
Solution 2:
Solution 3:
|
The
We need to debug this. |
Another solution would be to find the Windows kernel API responsible for mapping a defined page, and break on it. |
new solution: singlestep until ring 3 problem is that i'm not receiving single step event at some point... |
Blocked by libvmi/libvmi#636 |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
To be really useful, we need to be able to attach to a new process being created, and break on the entrypoint.
This address should be in the
Win32StartAddress
field of theETHREAD
.with the latest progress on
symbols
branch:the
Win32StartAddress
field contains an uncomplete/invalid address. is this an offset ???Next steps:
The text was updated successfully, but these errors were encountered: