{"repo":"hasherezade/tiny_tracer","free":true,"listed":false,"github":"https://github.com/hasherezade/tiny_tracer","clone":"git clone https://github.com/hasherezade/tiny_tracer.git","description":"A Pin Tool for tracing API calls etc","language":"C++","stars":1687,"topics":["intel-pintools","api-trace","reverse-engineering","dbi","malware-analysis"],"license":"GPL-2.0","category":"security-tools","readme_excerpt":"tiny tracer A Pin Tool for tracing: + API calls, including input and output of selected functions + defined local functions, and functions from statically linked libraries + selected instructions: RDTSC, CPUID, INT + inline system calls, including parameters of selected syscalls + transition between sections of the traced module (helpful in finding OEP of the packed module) + executed instructions in defined code fragments Evades some of the known anti-debug and anti-VM techniques Generates a report in a .tag format (which can be loaded into other analysis tools): i.e. 🚧 How to build It was tested with Intel Pin 4.2. You can build it on Windows or on Linux. Detailed descriptions available here. If you have any problems with building the project on Windows, you can use the test builds from the AppVeyor server. Select the platform, and then 'Artifacts'. Check the 'Console' output to see what version of Pin is required to use them. Then, follow the installation instructions. ⚙ Usage 📖 Details about the usage you will find on the project's Wiki. 🛠 Helpers For automatic generation of params.txt for API arguments tracing, try IAT-Tracer by YoavLevi WARNINGS + In order for Pin to work correctly, Kernel Debugging must be DISABLED . + In install32 64 you can find a utility that checks if Kernel Debugger is disabled ( kdb check.exe , source), and it is used by the Tiny Tracer's .bat scripts. This utility sometimes gets flagged as a malware by Windows Defender (it is a known false po","default_branch":null,"files":null,"tree":[],"storefront":"/r/hasherezade","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/hasherezade/tiny_tracer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}