miasm
Reverse engineering framework
minidump_to_pe Namespace Reference

Variables

 minidump = Minidump(open(sys.argv[1], 'rb').read())
 
 pe = PE()
 
 name = str(memory.name)
 
 protect = memory.pretty_protect
 
int protect_mask = 0x20
 
 addr
 
 address
 
 rawsize
 
 data
 
 content
 
 flags
 
 entry_point = minidump.threads.Threads[0].ThreadContext.Eip[0]
 
 AddressOfEntryPoint
 

Detailed Description

Minidump to PE example

Variable Documentation

◆ addr

minidump_to_pe.addr

◆ address

minidump_to_pe.address

◆ AddressOfEntryPoint

minidump_to_pe.AddressOfEntryPoint

◆ content

minidump_to_pe.content

◆ data

minidump_to_pe.data

◆ entry_point

minidump_to_pe.entry_point = minidump.threads.Threads[0].ThreadContext.Eip[0]

◆ flags

minidump_to_pe.flags

◆ minidump

minidump_to_pe.minidump = Minidump(open(sys.argv[1], 'rb').read())

◆ name

string minidump_to_pe.name = str(memory.name)

◆ pe

minidump_to_pe.pe = PE()

◆ protect

minidump_to_pe.protect = memory.pretty_protect

◆ protect_mask

int minidump_to_pe.protect_mask = 0x20

◆ rawsize

minidump_to_pe.rawsize