Skip to content

trace selected Ring3 program #9

Answered by Quentin01
johdcmlaker2000 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,

REVEN currently works with full-system traces only (ring0 + ring3) in all editions. You're correct that the Enterprise edition provides ways to shorten traces by allowing recording around a specific process using automatic binary recording or between arbitrary start/stop points using ASM stubs.

Working with full-system traces is leveraged in particular by the backward/forward data flow Taint feature which allows to follow data full system for investigations such as crash to data or data to crash.

Aside from trace generation, on the analysis side, the Ring and Process Filter feature, available in Axion GUI and Python API, allows to browse the trace while sticking to some ring and set o…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by johdcmlaker2000
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants