r2vmi icon indicating copy to clipboard operation
r2vmi copied to clipboard

Attach exisiting process: find rip in thread context

Open Wenzel opened this issue 7 years ago • 0 comments

Currently we attach to a process by listening to CR3 events.

We should enumerate the threads, pick the first one, find the thread context and read the value of rip where the thread is supposed to continue the execution.

Wenzel avatar Sep 09 '18 23:09 Wenzel