MCPcopy Create free account
hub / github.com/Phat3/PINdemonium / DumpProcess

Method DumpProcess

PINdemonium/InitFunctionCall.cpp:86–148  ·  view source on GitHub ↗

Dump the current process memory and try to reconstruct the PE from the dump using "oep" as Original Entry Point **/

Source from the content-addressed store, hash-verified

source not stored for this graph (policy: none)

Callers

nothing calls this directly

Calls 3

ScyllaDumpProcessAFunction · 0.85
GetExeModuleBaseFunction · 0.50
GetFilePathFromPIDFunction · 0.50

Tested by

no test coverage detected