LogicMem
Algorithms to recover kernel symbos, compute KASLR shift, locate task_struct and module when kallsyms is not available can be found in memoryReader.py
.
Part of logic rules can be found in rules.pl
Algorithms to recover kernel symbos, compute KASLR shift, locate task_struct and module when kallsyms is not available can be found in memoryReader.py
.
Part of logic rules can be found in rules.pl