v0.6 - Image Load Callback
Second sensor: every image (DLL/EXE) loaded into any process is captured, pushed into the existing queue, and written to the log through the standard pipeline.
Added
image_callback.c/.h:PsSetLoadImageNotifyRoutinecallback, captures image base, size, properties, system/mapped/partial-map flags, signature level/type, and full image path- Registered/unregistered in
DriverEntry/DriverUnload, after the process callback (unregistered first, symmetric teardown order) event_types.h:KDAMON_IMAGE_LOAD_EVENT_DATA(PID, image base/size, properties, three BOOLEAN-as-ULONG flags, signature level/type, fixed-size image name)log_writer.c:KdaMonLogWriterWriteImageEvent, dispatched via switch inKdaMonLogWriterWriteEvent