Based on Brandon Azad's ida_kernelcache
Requirement
How to use?
iometa -n -A [kernelcache] > /tmp/kernel.txt
jtool2 --analyze [kernelcache]; mv [kernelcache companion file] /tmp/kernel_jtool2.txt
- IDA에서 script ->
ida_kernelcache.py
를 로딩 - python prompt에
kc.kernelcache_process()
실행