mirror of
https://github.com/toneillcodes/dll-research
synced 2026-08-09 13:13:50 +00:00
Documentation updates
This commit is contained in:
@@ -12,12 +12,15 @@ Windows Dynamic-Link Library research & offensive tooling.
|
||||
Passively monitoring active APIs.
|
||||
* **Frida Dynamic API Monitoring Telemetry Agent (`api-monitor.py`):** A dynamic instrumentation tool that injects a runtime JavaScript payload into target processes to automatically hook and track exported functions. It leverages asynchronous retry loops for deferred modules and filters out duplicate calls to stream clean, structured API telemetry directly to a JSONL log.
|
||||
* **PE Dormant Export Analyzer (`find-dormant-blocks.py`):** A static analysis tool that parses a DLL's export table and SEH exception directories (`.pdata`) to map function boundaries linearly in memory. It cross-references these mappings against runtime telemetry and custom blacklists to identify contiguous, unused code blocks that meet specified capacity thresholds.
|
||||
- [Documentation](/documentation/find-dormant-blocks.md)
|
||||
|
||||
### [Stability Harness](stability-harness.md)
|
||||
* **Stability Campaign Plan Generator (`make-stability-plan.py`):** A data transformation utility that converts raw CSV binary audit sheets into structured JSON execution plans. It adaptively shifts between granular function-level testing arguments or broad full-module section overwrites based on available metadata.
|
||||
- [Documentation](\documentation\make-stability-plan.md)
|
||||
* **Process Stability Campaign Harness (`stability-harness.py`):** An automated testing orchestration engine designed to execute and monitor the generated parametric process stability profiles. It launches target binaries, tracks the lazy loading of associated DLL runtime dependencies, integrates concurrent module-stomping companion tools, and captures kernel exit codes into structured JSONL logging manifests.
|
||||
- [Documentation](/documentation/stability-harness.md)
|
||||
|
||||
### [Process Profiles](process-profiles\README.md)
|
||||
### [Process Profiles](process-profiles/README.md)
|
||||
#### Summary
|
||||
Compiled process profiles for common applications and Operating Systems. YMMY.
|
||||
* [Windows Server 2025 DC](process-profiles\Windows-Server-2025-DC\README.md)
|
||||
* [Windows Server 2025 DC](process-profiles/Windows-Server-2025-DC/README.md)
|
||||
@@ -6,4 +6,5 @@ Monitoring active APIs.
|
||||
* [`api-monitor.py`](api-monitor.py)
|
||||
- **Frida Dynamic API Monitoring Telemetry Agent**: A dynamic instrumentation tool that injects a runtime JavaScript payload into target processes to automatically hook and track exported functions. It leverages asynchronous retry loops for deferred modules and filters out duplicate calls to stream clean, structured API telemetry directly to a JSONL log.
|
||||
* [`find-dormant-blocks.py`](find-dormant-blocks.py)
|
||||
- **PE Dormant Export Analyzer**: A static analysis tool that parses a DLL's export table and SEH exception directories (`.pdata`) to map function boundaries linearly in memory. It cross-references these mappings against runtime telemetry and custom blacklists to identify contiguous, unused code blocks that meet specified capacity thresholds.
|
||||
- **PE Dormant Export Analyzer**: A static analysis tool that parses a DLL's export table and SEH exception directories (`.pdata`) to map function boundaries linearly in memory. It cross-references these mappings against runtime telemetry and custom blacklists to identify contiguous, unused code blocks that meet specified capacity thresholds.
|
||||
- [Documentation](/documentation/find-dormant-blocks.md)
|
||||
@@ -1,6 +1,6 @@
|
||||
# Process Profiles
|
||||
## Windows Server 2025 Datacenter
|
||||
* [Browser Profiles](process-profiles\Windows-Server-2025-DC\browser-profiles.md)
|
||||
* [Editor Profiles](process-profiles\Windows-Server-2025-DC\editor-profiles.md)
|
||||
* [Utility Profiles](process-profiles\Windows-Server-2025-DC\utility-profiles.md)
|
||||
* [Browser Profiles](process-profiles/Windows-Server-2025-DC/browser-profiles.md)
|
||||
* [Editor Profiles](process-profiles/Windows-Server-2025-DC/editor-profiles.md)
|
||||
* [Utility Profiles](process-profiles/Windows-Server-2025-DC/utility-profiles.md)
|
||||
|
||||
|
||||
@@ -5,5 +5,7 @@ Testing harness to evaluate the stability of an application.
|
||||
## Index
|
||||
* [`make-stability-plan.py`](make-stability-plan.py)
|
||||
- **Stability Campaign Plan Generator**: A data transformation utility that converts raw CSV binary audit sheets into structured JSON execution plans. It adaptively shifts between granular function-level testing arguments or broad full-module section overwrites based on available metadata.
|
||||
- [Documentation](\documentation\make-stability-plan.md)
|
||||
* [`stability-harness.py`](stability-plan.py)
|
||||
- **Process Stability Campaign Harness**: An automated testing orchestration engine designed to execute and monitor the generated parametric process stability profiles. It launches target binaries, tracks the lazy loading of associated DLL runtime dependencies, integrates concurrent module-stomping companion tools, and captures kernel exit codes into structured JSONL logging manifests.
|
||||
- **Process Stability Campaign Harness**: An automated testing orchestration engine designed to execute and monitor the generated parametric process stability profiles. It launches target binaries, tracks the lazy loading of associated DLL runtime dependencies, integrates concurrent module-stomping companion tools, and captures kernel exit codes into structured JSONL logging manifests.
|
||||
- [Documentation](/documentation/stability-harness.md)
|
||||
Reference in New Issue
Block a user