A
license-
qualityA
maintenanceReverse engineering against a running Windows process instead of the file on disk: memory reads, pattern and value scanning, disassembly of the code that actually executed, resolved IAT thunks, caller-chain tracing, and structure recovery. Complements the Ghidra and IDA servers rather than replacing them — correlate_addr maps a runtime address back to a module and RVA.
MIT