-
Notifications
You must be signed in to change notification settings - Fork 13
Open
Description
Some obfuscated applications statically link libxpc, meaning they make all the raw Mach calls directly. This tool will not work on such binaries. More investigation is needed into how to parse the binary representation of XPC messages. The messages appear to start with "CPX@" (@XPC backwards).
Metadata
Metadata
Assignees
Labels
No labels