trolldbois / python-haystack

Process heap analysis framework - Windows/Linux - record type inference and forensics
http://trolldbois.blogspot.com/search?q=python-haystack
GNU General Public License v3.0
94 stars 33 forks source link

Look at the state of art papers #33

Closed trolldbois closed 7 years ago

trolldbois commented 7 years ago

https://scholar.google.com/scholar?cluster=4083491147070699259&hl=en&as_sdt=0,5&sciodt=0,5

MemPick: High-Level Data Structure Detection in C/C++ Binaries

trolldbois commented 7 years ago

Identification of data structure in memory dump of executed sample

Identification of data structures in dynamic execution of samples

Terminology

trolldbois commented 7 years ago

move to wiki https://github.com/trolldbois/python-haystack/wiki/State-of-art-reference