-
-
[转帖]Process Stalker v1.1 by Pedram Amini
-
发表于: 2008-2-12 22:13 2833
-
Process Stalker v1.1 by Pedram Amini
Process Stalking is a term coined to describe the combined process of run-time profiling, state mapping and tracing. Consisting of a series of tools and scripts the goal of a successful stalk is to provide the reverse engineer with an intuitive visual interface to filtered, meaningful, run-time block-level trace data.
The Process Stalker suite is broken into three main components; an IDA Pro plug-in, a stand alone tracing tool and a series of Python scripts for instrumenting intermediary and GML graph files. The generated GML graph definitions were designed for usage with a freely available interactive graph visualization tool.
Data instrumentation is accomplished through a series of Python utilities built on top of a fully documented custom API. Binaries, source code and in-depth documentation are available in the bundled archive. An indepth article was written and released on OpenRCE.org detailing step by step usage of Process Stalker, the article is a good starting point for understanding the basics behind the tool set.
Manual:
http://pedram.redhive.com/process_stalking_manual/
API docs:
http://pedram.redhive.com/process_stalking_manual/ps_api_docs/
赞赏
他的文章
谁下载
cwx
ylp1332
鸡蛋壳
LOCKLOSE
Clone
prik
ffsj
yiyiguxing
poll
fuqiang
sabason
黑色猎鹰
olidibag
mbaightttt
jesss
suntiger
qdicao
codeapp
kimkundo
tashika
xqx
ymfhcn
fashioncn
khongninh
Mutante
shuhui
Cyane
angelbox
liyub
OldBody
chengww
xsystem
salwtp
pkuyn
aniuzhang
leebuwei
yulinxie
CaiHuan
dengzheng
llltmax
看原图
赞赏
雪币:
留言: