3 ms·
SoftICE brings back memories... although now that you're using Bochs, you can just use Bochs' internal debugger to do the same thing. Heck you can connect the B
by ipython 3y ago
SoftICE brings back memories... although now that you're using Bochs, you can just use Bochs' internal debugger to do the same thing. Heck you can connect the Bochs debugger to IDA Pro: https://hex-rays.com/products/ida/support/idadoc/1329.shtml https://hex-rays.com/products/ida/support/idadoc/1329.shtml.
I've used the Bochs debugger many times to debug DOS apps and to even do things like create an unencrypted forensic image of a full-disk encrypted drive (obviously assuming you have the encryption key, no magic there).
- anthk 3y agoBochs is an unknown beast. The IPC clock might be not so precise to adjust, but it can emulate highend i7's. Slowly, yes, but you will fake every instruction to the guest. And, you know, you can RE hard stuff like malware in no time.
- tdullien 3y agoUsing Bochs to step through aggressive obfuscating packers was one of the important ingredients to the malware analysis infrastructure I built 2005-2011 in my first company. Bonus points for stepping the same malware in Bochs and Qemu simultaneously to identify trace divergence; detection then needs to detect both in one stroke.