- Aug 29, 2017
- Security
Windows _EX_FAST_REF Pointers and Virtual Machine Introspection
Last week I was working on a VMI-based malware unpacker for Linux and Windows when I came across an interesting problem. I was trying to implement a method that would, given a virtual address and process ID, return the address range of the memory segment it belongs to using VMI …