DiscoverOALabsDisable ASLR For Easier Malware Debugging With x64dbg and IDA Pro
Disable ASLR For Easier Malware Debugging With x64dbg and IDA Pro

Disable ASLR For Easier Malware Debugging With x64dbg and IDA Pro

Update: 2019-06-11
Share

Description

This tutorial covers how to disable ASLR in your debugging VM to speed up your debugging when using x64dbg and IDA Pro.We have a short blog post here:
https://oalabs.openanalysis.net/2019/06/12/disable-aslr-for-easier-malware-debugging/

The registry value you want to add is:
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\MoveImages

Feedback, questions, and suggestions are always welcome : )

Sergei https://twitter.com/herrcore
Sean https://twitter.com/seanmw

As always check out our tools, tutorials, and more content over at https://www.openanalysis.net

#ReverseEngineering #Debugging #ASLR #x64dbg
Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Disable ASLR For Easier Malware Debugging With x64dbg and IDA Pro

Disable ASLR For Easier Malware Debugging With x64dbg and IDA Pro

OALabs