Re: [PATCH 3/3] contrib/elf2dmp: add PE name check and Windows Server 2022 support

2021-11-04 Thread Yuri Benditovich
On Wed, Nov 3, 2021 at 6:13 PM Viktor Prutyanov wrote: > > Since its inception elf2dmp has checked MZ signatures within an > address space above IDT[0] interrupt vector and took first PE image > found as Windows Kernel. > But in Windows Server 2022 memory dump this address space range is > full of

[PATCH 3/3] contrib/elf2dmp: add PE name check and Windows Server 2022 support

2021-11-03 Thread Viktor Prutyanov
Since its inception elf2dmp has checked MZ signatures within an address space above IDT[0] interrupt vector and took first PE image found as Windows Kernel. But in Windows Server 2022 memory dump this address space range is full of invalid PE fragments and the tool must check that PE image is 'ntos