OVALProject / Sandbox

The OVAL Language Sandbox
http://oval.mitre.org/language/sandbox.html
44 stars 36 forks source link

add ASLR status entity to the win-def:process58_state and <win-sc:process58_item #103

Open djhaynes opened 11 years ago

djhaynes commented 11 years ago

Details of this request are outlined in the following developer list message: http://making-security-measurable.1364806.n2.nabble.com/Developer-Days-Artifact-Hunting-Slides-tp6463048p6463048.html See slide 11.

djhaynes commented 11 years ago

The ASLR information seems to only be available via the PE Header, which means it will be added to the pefile test, instead of the process58_test. (http://msdn.microsoft.com/en-us/magazine/ms809762.aspx)