Skip to content

B1Fr0st/lokidumper

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

14 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Usage

just implement your driver read primitive & init in memory/your-driver.rs and change type MEMORY = windows::WindowMemory to type MEMORY = your-driver::MyMemory in main.rs

comes with an example windows RPM implementation by default

TODO:

Fixups / relocations

Add encrypted / blank check to ensure we only dump decrypted pages (entropy check?)

About

Simple, easily extensible process dumping tool designed to bypass Theia protections

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages