Radare2 VMI IO and debugger plugins.
These plugins allow you to debug a remote process running in a VM, from the hypervisor-level, leveraging Virtual Machine Introspection.
Based on Libvmi to access the VM memory and listen on hardware events.
- Intercept a process by name/PID
- Read the registers
- Single-step the process execution
- Set breakpoints
- Load Rekall symbols
$ git clone https://github.com/Wenzel/r2vmi.git
$ make install
Note: if pkgconfig fails, you need to: