Also, kernel crashdump support was added, so you can also use it as a kind of Volatility framework. But faster.
Example code:
github.com/vmi-rs/vmi/b...
Also, kernel crashdump support was added, so you can also use it as a kind of Volatility framework. But faster.
Example code:
github.com/vmi-rs/vmi/b...
This time about MmScrubMemory. An innocuous looking function that has bitten my ass several times in the last several years. And if you're developing a hypervisor, it might've bitten yours, too.
wbenny.github.io/2024-11-21-m...
This time about MmScrubMemory. An innocuous looking function that has bitten my ass several times in the last several years. And if you're developing a hypervisor, it might've bitten yours, too.
wbenny.github.io/2024-11-21-m...