Internals of Windows Memory Management (not only) for Malware Analysis

Carsten Willems · MADOC (University of Mannheim) · 2011

This document presents insights from extensive reverse engineering efforts of the memory management mechanisms of Windows XP. The focus lies on (1) the mechanisms which are used to map executable modules into the address space and (2) the role of the page fault handler in this context.

Read the paper · More papers on PaperTik