from cmd or Run
powershell -Command "Start-Process cmd -Verb RunAs"
import os | |
import pefile | |
import json | |
INTERESTING_DLLS = [ | |
'kernel32.dll', 'comctl32.dll', 'advapi32.dll', 'comdlg32.dll', | |
'gdi32.dll', 'msvcrt.dll', 'netapi32.dll', 'ntdll.dll', | |
'ntoskrnl.exe', 'oleaut32.dll', 'psapi.dll', 'shell32.dll', | |
'shlwapi.dll', 'srsvc.dll', 'urlmon.dll', 'user32.dll', |
from cmd or Run
powershell -Command "Start-Process cmd -Verb RunAs"
import idautils | |
ea = 0x000000140013188 | |
name = ida_name.get_ea_name(ea) | |
print("found") | |
# get xrefs to function | |
xrefs = [x for x in idautils.CodeRefsTo(ea, 0)] | |
for func in xrefs: |