pyrebox
pyrebox copied to clipboard
Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU
Hi, CVE-2020-14364 apparently allows arbitrary code execution in QEMU in versions before 5.2.0. Pyrebox QEMU fork seem to be in version 4.0.0. Is it vulnerable to this issue? References :...
Hi, I am trying to build pyrebox on Debian sid. When building qemu, I get the following error in the config.log file: ``` config-temp/qemu-conf.c: In function ‘main’: config-temp/qemu-conf.c:2:25: error: null...
data:image/s3,"s3://crabby-images/45093/450934a6c3e4db60fc11819475c902f29c79348a" alt="image" data:image/s3,"s3://crabby-images/9b154/9b154f7bffea15590bdd86a73fa6729372f6f324" alt="image" data:image/s3,"s3://crabby-images/699b0/699b03fc92817e0f0f0d8f8ce1303fa98879b956" alt="image" data:image/s3,"s3://crabby-images/704d9/704d93fe6f319dab5590b8be30034939d423d1e7" alt="image" As shown in the picture above,i modified your code. I inserted my read-write record function in the deliver_callback function of the callbacks.cpp file. I only record...
I have a 32-bit x86 OS that is close to Linux, BSD based, and I was wondering what some high level steps I will need to take to add support...
Hi! My guest OS is Debian 9. My host is Ubuntu18.04. I get my volatility profile from [volatilityfoundation/profiles Github](https://github.com/volatilityfoundation/profiles). It seems that this profile does not work. I wonder if...
Create configuration option to decide how frequently PyREBox should search for init_task.
I tried to build pyrebox on my debian machine and it fails during compilation. Here the steps: ``` $ apt-get install build-essential zlib1g-dev pkg-config libglib2.0-dev binutils-dev libboost-all-dev autoconf libtool libssl-dev...
usb_add does no longer exist (https://wiki.qemu.org/ChangeLog/2.11). Malware monitor 2 is not properly documented, and new features such as file system inspection, symbol caches, volatility3, are not documented.
Hey all, Super interested to play with this. I see you have a Dockerfile created. Unfortunately, I cannot create an automated build against your github account since I do not...
- [x] Listing processes during system boot and system operation - [x] Monitoring individual address spaces (processes) - [ ] Monitoring individual threads separately - [x] Extracting module information for...