tklengyel / drakvuf

DRAKVUF Black-box Binary Analysis
https://drakvuf.com
Other
1.06k stars 253 forks source link

need guidance towards drakvuf tracing #1376

Open mohitbhatt-du opened 2 years ago

mohitbhatt-du commented 2 years ago

Dear Tamas K. Lengyel Sir,

From previous instructions by you, we have successfully generated some logs.

In logs we found some extra features like -

1) Syscall Time 2) Sysret Time 3) Delayintervals 4) Process Handler 5) Process Information Class 6) Process Information 7) Return Length 8) CR3 Value 9) Procmon 10) Filetracer 11) Sysnet 12) File Extractor 13) Syscall 14) Poolmon 15) Delaymon 16) Objmon

We now request you to guide us by providing any documentation or description of these features and what they are indicating.

Kindly provide your guidance so that we can move ahead further. Thanks

Regards Mohit

hexrays4711 commented 1 year ago

e.g. https://learn.microsoft.com/en-us/windows/win32/api/ https://learn.microsoft.com/en-us/sysinternals/resources/windows-internals https://learn.microsoft.com/en-us/sysinternals/resources/