

GitHub - Wenzel/r2vmi: Radare2 VMI IO and debugger plugins
source link: https://github.com/Wenzel/r2vmi
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

README.md
r2vmi
Radare2 VMI IO and debugger plugins.
These plugins allow you to debug remote process running in a VM, from the hypervisor-level, leveraging Virtual Machine Introspection.
Based on Libvmi
to access the VM memory and listen on hardware events.
What works:
- Intercept a process by name/PID
- Read the registers
- Single-step the process execution
- Set breakpoints
- Load Rekall symbols
Demo
Requirements
Xen 4.6
libvmi
radare2
pkg-config
Setup
$ make
$ make install
Note: if pkgconfig
fails, you need to:
export PKG_CONFIG_PATH=/usr/lib/pkgconfig
Usage
You need a virtual machine configured on top of Xen
, and a process name/pid to intercept
$ r2 vmi://<vm_name>:<name/pid>
Example:
$ r2 vmi://win7:firefox
Recommend
-
137
radareorg/radare2: UNIX-like reverse engineering framework and command-line toolset...
-
121
apk-anal Android APK analyzer based on radare2 and others. What does it do? It's an static analys tool for APK files based on radare2, apktool and APKiD. It tries to quickly determine interesting features like
-
143
-
109
-
113
jupyter-radare2 This is a simple radare2 Jupyter kernel, that can be used to make interactive radare2 tutorials, or take adv...
-
148
README.md
-
72
0×01 前言 使用 radare2 逆向 iOS Swift 应用程序,我们将使用iGoat应用程序。我们的目标是反编译iOS Swift应用程序的外观。这是以前iGoat Objective C项目的Swift版本。使用OWASP iGoat,您可以学习iOS Swift应用...
-
67
工具介绍 Radare2基于Radare开发,并支持第三方二进制文件以提供更多的实用功能。Radare作为一款取证工具,提供了可编辑的命令行十六进制编辑器,可直接打开磁盘文件,但后来又添加了分析模块、反编译模块、调试程序和远程gdb服...
-
57
Ocean Lotus Group,也被称之为APT32,这个黑客组织此前主要的攻击目标以越南、老挝和菲律宾等东亚国家为主,虽然私营企业是该组织的主要目标,...
-
8
User Research Crash Course for Product ManagersA quick and dirty foundational understanding of User Research
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK