lucasg
lucasg
Ok that was a fairly complicated bug to track down. What happened is, on Debug build `Dependencies.exe` failed to load the packaged `msvcp140d.dll` so -weirdly enough- the CLR loader folded...
Yeah, totally agree. However to prevent file locking I need to change completely my PE parser (I currently use ProcessHacker's phlib). It's in my TODO list, but unfortunately there are...
I'm implemented a pretty rudimentary version: you can choose it in the "Options>Preferences>Use BinaryCache" but the settings is application wide **and you need to restart Dependencies** since BinaryCache is implemented...
you can add folder to search in "Options/Customize Folders". Example with C:\Windows\System32\ntoskrnl.exe : data:image/s3,"s3://crabby-images/225fe/225fede0e0530d9516fc404f31b546d25e93131b" alt="image" Adding C:\Windows\System32\drivers as a valid folder : data:image/s3,"s3://crabby-images/68d5e/68d5e094bc5127505e11c8a6aa4e2f336bebd4f2" alt="image" Result : data:image/s3,"s3://crabby-images/360aa/360aab2bac5ae3df4571b656099a62d95304feb0" alt="image" All kext resolved to *.sys...
hmm, weird I actually tried to look into PATH env var : ```C# // 7. Find in PATH string PATH = Environment.GetEnvironmentVariable("PATH"); List PATHFolders = new List(PATH.Split(';')); // Filter out...
The actual computation of hints is currently wacky af, thanks for the remainder
Ok I checked the MS spec, and there is no hint information for exports, only for imports : https://docs.microsoft.com/en-us/windows/win32/debug/pe-format#the-edata-section-image-only So ```depends`` is in the wrong here, I don't know how...
That's what the "modules" listview is for, no ? Anyway, you can also find the same list in the "Module Search Order" popup : data:image/s3,"s3://crabby-images/cbc19/cbc1984514952cad0154c3c1b6d365efc7b94062" alt="image" You can also see which...
Exactly. If one day I wanted to implement this feature, it would be a separate tool anyway. In the meantime ProcMon, [wtrace](https://github.com/lowleveldesign/wtrace) and a good breakpoint with Windbg can do...
Huh, all these years that I've used Dependency Walker I never though about what "PE" and "PI" meaning was. Not gonna lie, it would be a PITA to do what...