volatilityfoundation / community

Volatility plugins developed and maintained by the community
336 stars 144 forks source link

antianaysis plugin #9

Closed Itaykr closed 8 years ago

Itaykr commented 8 years ago

Antianalysis find windows api calls which identified with anti-debugging/analysis techniques. When this plugin finds a suspicious api call it outputs the last 4 instructions using disassembly in order to show the function's argument etc..

gleeda commented 8 years ago

Cool thanks!