Cross-platform Support for Windows Memory Dumps

Offen
#653 3 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Anfängerfreundlichkeit
25/100
Issue-Typ
Feature
Klarheit
Muss geklärt werden
Aktivitätsstatus
Veraltet
Tech-Stack
cpp

Rechercherichtung

Reproduce the reported behavior by opening a Windows memory dump of a PE file and comparing the hex view's "Raw" and "PE" options. Start from the disassembler's PE recognition and memory-dump handling paths; done means the dump is identified as PE and functions are shown instead of an unchanged raw view.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Component: Core Effort: Medium File Format: PE Impact: Low

Hi there,

I want to disassemble a memory dump of a PE file. Upon startup binary ninja goes into a hex view without identifying any functions. I guess the disassembler knows that this is a PE file, because in the bottom-right corner it shows me two options "Raw" and "PE". However, switching to PE doesn't change anything ("Raw" remains as the selected option).

Vorherrschende Sprache
C++
Sterne
1.3k
Forks
298
Ø Merge
5 T. 5 Std.
Gemergte PRs (30 T.)
19

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus Vector35/binaryninja-api

Alle Issues in Vector35/binaryninja-api

Ähnliche Issues

Weitere Issues zu C++

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.