Internals of Windows Memory Management (not only) for Malware Analysis
Carsten Willems · MADOC (University of Mannheim) · 2011
This document presents insights from extensive reverse engineering efforts of the memory management mechanisms of Windows XP. The focus lies on (1) the mechanisms which are used to map executable modules into the address space and (2) the role of the page fault handler in this context.