Mark Jansen retweetledi

Mark Jansen
616 posts

















You can trace calls to VslpEnterIumSecureMode ("enter/exit" into VTL 1) through the (the value is undocumented?) PERF_VTL1_ENTER ETW perf info mask value and get information about the type of secure call call which occurred (and PID/TID info). The event data is also undocumented.








👋 Please join us in welcoming @RolfRolles as Hex-Rays’ new Chief Scientist! Rolf brings decades of RE expertise, with standout work in obfuscation, decompilation, and software protection. At Hex-Rays, he’ll lead research into next-gen decompilation and automated program understanding to keep our tools at the cutting edge. We’re thrilled to have him on board! #ReverseEngineering #IDAPro #BinaryAnalysis #Decompilation
