Files
wavestone-cdt-edrsandblast/EDRSandblast/Includes
Maxime Meignan bf749f54c7 PE parser: added a feature to parse a PE directly from kernel memory
Could be used in the future to resolve export instead of a
suspicious LoadLibrary("ntoskrnl.exe")
2023-11-03 16:13:13 +01:00
..
2021-11-08 09:54:05 +01:00