-
parse mpasbase.vdm and extract the emulated file and its contents
which in the Windows Defender.
-
before parse the .vdm files, we have to unpack it.
-
you can do this by using "vdm_decomp.ps1".
-
since python does not support the zlib.inflate algorithm,
unpacking .vdm couldn't implement yet.
-
so you have to use other .vdm decompression tools.
( "vdm_decomp.ps1" is not my work)
-
-
Notifications
You must be signed in to change notification settings - Fork 1
orca-eaa5a/pyvdmextract
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
Extract the emulated files in Windows Defender signature database
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published