-
Notifications
You must be signed in to change notification settings - Fork 57
Home
ktwo/ShaneK2 edited this page Jul 23, 2017
·
13 revisions
-
Download / run setup from publish.zip ⇒ https://github.com/ShaneK2/inVtero.net/blob/master/quickdumps/publish.zip
-
MSDIA registered "regsvr32 msdia140.dll" (can skip on dev boxes usually already registered)
-
-
Memory integrity monitoring with secure hash
-
Forensics/DFIR
-
Reversing/Active-Passive debugging
-
Edit a suspended VM and then resume it. No debugger in the guest needed.
-
The embedded shell is an IronPython x64 instance and is now the only supported mechanism for CLI use.
Analyze.py is run by default on startup.
It also matches the logical and physical process lists to ensure that there does not exist a hidden process. Please extend it but in the future will be higher order analytics, pointer/structure type information and integrity checks.