Symbolic Triage

This repository contains the supporting materials for the “Symbolic Triage” blog post.

  • is the main utility, which implements the symbolic execution and tracing of the Procmon64.exe crashes
    • Targets Process Monitor version 3.91
    • Is intended to be used as an example of using Triton hand in hand with the Windows debugging API
  • contains windows types used for using the debugger API
  • procmoncrash.xx contains an xx file of a minimized crash, as described here


