When is loadmainmodule_notify called?

12 views
Skip to first unread message

Brendan Dolan-Gavitt

unread,
Apr 24, 2018, 4:19:26 PM4/24/18
to decaf-platform-discuss
Hi,

We've recently been looking at the CFI code and attempting to re-implement it under PANDA so we can look for exploits in our Malrec dataset (https://giantpanda.gtisc.gatech.edu/malrec/dataset/). However, we have found a callback that doesn't seem to be implemented in DECAF but is used in the system_cfi plugin: loadmainmodule_notify.

When is this callback triggered? Is it a) when the process is first seen in the process list, or b) when the main module (the .exe) is first seen in the module list?

Thanks,
Brendan
Reply all
Reply to author
Forward
0 new messages