Open williballenthin opened 1 year ago
With some parsing we can extract CRT strings (and code/function association) from .lib
/.obj
files.
for Delphi strings here's an existing database: https://github.com/dzzie/MAP/blob/master/delphi_filter.txt
Visual Studio contains source code (.c
, .cpp
, .h
, .asm
) as well as .lib
and .obj
files we can parse for run-time related strings.
install steps for many MSVC configurations: https://github.com/mandiant/siglib/blob/fe945b3030028fb915d5e4b0ac8aaa9514a3ae90/Dockerfile#LL54C1-L121C1
initial lib/obj db: https://github.com/mandiant/flare-floss/commit/722f0e3c840d4af597785573547ebc77be2858d5 parsed via JH
From manual analysis of internal GP database: