Files
mxaccess/captures/083-frida-buffered-plain-advise-hooked/frida-events.tsv
T
Joseph Doherty fe2a6db786
rust / build / test / clippy / fmt (push) Has been cancelled
Initial project state: .NET reference, design, Rust port (M0+M1), evidence
Layout:
- src/                    .NET 10 x64 reference: MxNativeCodec, MxNativeClient,
                          MxAsbClient, probes, tests, harnesses. Executable spec.
- design/                 Architectural plan for the Rust port (M0–M6), error
                          model, protocol invariants, risks (R1–R16), adversarial
                          review log (review.md).
- rust/                   Rust workspace. M0 skeleton + M1 codec parity.
                          mxaccess-codec: 215 unit tests + 2 cross-implementation
                          parity tests (byte-identical against .NET reference).
                          Other crates are M0 stubs awaiting M2+.
- captures/               Frida + netsh + pcap evidence per CLAUDE.md
                          ("captures are evidence, not throwaway logs").
- analysis/               Decompiled C# (frida/proxy/decompiled-*),
                          Ghidra exports for native DLLs (`exports/` only —
                          working state at `projects/` and AVEVA's input
                          binaries at `input/` are gitignored).
- docs/                   Reverse-engineering reference docs.
- tools/                  Setup-LiveProbeEnv.ps1 (Infisical credential fetcher),
                          Compute-Crc.ps1 (.NET parity helper).
- .github/workflows/      Rust CI: fmt + build + test + clippy on Windows.
- LICENSE                 MIT (Joseph Doherty, 2026).

Verified:
- cargo test --workspace → 217 passed (215 unit + 2 .NET parity), 0 failed
- cargo clippy --workspace -- -D warnings → clean
- cargo fmt --all -- --check → clean
- cargo publish --dry-run -p mxaccess-codec → packages cleanly

Excluded from history (see .gitignore):
- **/bin, **/obj, **/target — build artifacts
- analysis/ghidra/projects/ — Ghidra working state (regenerable)
- analysis/ghidra/input/ — AVEVA proprietary DLLs (vendor IP)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-05 06:21:00 -04:00

15 KiB

1timeeventmodulenameecxretvalargscandidate_indexcandidate_sizecandidate_ptrvalue_hitshex
22026-04-25T21:03:40.659Zhook.installedLmxProxy.dllCLMXProxyServer.Write.variantA[]
32026-04-25T21:03:40.660Zhook.installedLmxProxy.dllCLMXProxyServer.Write.variantB[]
42026-04-25T21:03:40.660Zhook.installedLmxProxy.dllCLMXProxyServer.WriteSecured.variantA[]
52026-04-25T21:03:40.661Zhook.installedLmxProxy.dllCLMXProxyServer.WriteSecured.variantB[]
62026-04-25T21:03:40.661Zhook.installedLmxProxy.dllCLMXProxyServer.AddBufferedItem[]
72026-04-25T21:03:40.662Zhook.installedLmxProxy.dllCLMXProxyServer.SetBufferedUpdateInterval[]
82026-04-25T21:03:40.662Zhook.installedLmxProxy.dllCLMXProxyServer.AdviseSupervisory[]
92026-04-25T21:03:40.663Zhook.installedLmxProxy.dllCProxy_ILMXProxyServerEvents2.Fire_OnBufferedDataChange[]
102026-04-25T21:03:47.310Zhook.installedLmx.dllMxConnection.PrebindReference[]
112026-04-25T21:03:47.311Zhook.installedLmx.dllMxConnection.UserRegisterPreboundReference[]
122026-04-25T21:03:47.312Zhook.installedLmx.dllIMxReference.GetMxHandle[]
132026-04-25T21:03:47.313Zhook.installedLmx.dllAccessManager.FixUpMxHandle[]
142026-04-25T21:03:47.314Zhook.installedLmx.dllPreboundReference.Resolve[]
152026-04-25T21:03:47.314Zhook.installedLmx.dllPreboundReference.OnPlatformResolveReferenceResults[]
162026-04-25T21:03:47.315Zhook.installedLmx.dllPreboundReference.OnSetAttributeResult[]
172026-04-25T21:03:47.411Zhook.installedNmxAdptr.dllCNmxAdapter.TransferData[]
182026-04-25T21:03:47.412Zhook.installedNmxAdptr.dllCNmxAdapter.ProcessDataReceived[]
192026-04-25T21:03:47.413Zhook.installedNmxAdptr.dllCNmxAdapter.PutRequest[]
202026-04-25T21:03:47.414Zhook.installedNmxAdptr.dllCNmxAdapter.PutRequestEx[]
212026-04-25T21:03:47.418Zlmx.fixup-mxhandle.enterLmx.dllAccessManager.FixUpMxHandle[]
222026-04-25T21:03:47.419Zlmx.fixup-mxhandle.leaveLmx.dllAccessManager.FixUpMxHandle0x5de844[]
232026-04-25T21:03:47.419Zlmx.fixup-mxhandle.enterLmx.dllAccessManager.FixUpMxHandle[]
242026-04-25T21:03:47.420Zlmx.fixup-mxhandle.leaveLmx.dllAccessManager.FixUpMxHandle0x5de844[]
252026-04-25T21:03:47.518Zcall.enterLmxProxy.dllCLMXProxyServer.SetBufferedUpdateInterval0x5def18["0x5b78ff0","0x1","0x3e8"]
262026-04-25T21:03:47.518Zcall.leaveLmxProxy.dllCLMXProxyServer.SetBufferedUpdateInterval0x0[]
272026-04-25T21:03:47.520Zcall.enterLmxProxy.dllCLMXProxyServer.AddBufferedItem0x5def0c["0x5b78ff0","0x1","0x5deeac","0x5dee84","0x5deef0"]
282026-04-25T21:03:47.521Zlmx.mxhandle.readLmx.dllIMxReference.GetMxHandle0x5ded4c[]
292026-04-25T21:03:47.522Zlmx.prebound-resolve.enterLmx.dllPreboundReference.Resolve[]
302026-04-25T21:03:47.523Zlmx.mxhandle.readLmx.dllIMxReference.GetMxHandle0x5decec[]
312026-04-25T21:03:47.523Zlmx.mxhandle.readLmx.dllIMxReference.GetMxHandle0x5decd8[]
322026-04-25T21:03:47.524Zlmx.mxhandle.readLmx.dllIMxReference.GetMxHandle0x5decec[]
332026-04-25T21:03:47.525Zlmx.prebound-resolve.leaveLmx.dllPreboundReference.Resolve0x70fe1e01[]
342026-04-25T21:03:47.525Zlmx.mxhandle.readLmx.dllIMxReference.GetMxHandle0x5ded4c[]
352026-04-25T21:03:47.525Zcall.leaveLmxProxy.dllCLMXProxyServer.AddBufferedItem0x0[]
362026-04-25T21:03:47.527Zlmx.user-register-prebound.enterLmx.dllMxConnection.UserRegisterPreboundReference0x8f86b3c[]
372026-04-25T21:03:47.528Zlmx.user-register-prebound.leaveLmx.dllMxConnection.UserRegisterPreboundReference0x0[]
382026-04-25T21:03:47.653Znmx.enterNmxAdptr.dllCNmxAdapter.PutRequest0x1["0x8eac738","0x1","0x1","0x1","0x2","0x0","0x13a","0x8eb0648","0x5debdc","0x9299463d"]010x2
392026-04-25T21:03:47.653Znmx.enterNmxAdptr.dllCNmxAdapter.PutRequest0x1["0x8eac738","0x1","0x1","0x1","0x2","0x0","0x13a","0x8eb0648","0x5debdc","0x9299463d"]13140x8eb064817 01 00 01 01 00 01 00 00 00 65 00 71 00 0a 00 00 00 00 00 08 6a 00 00 00 40 00 00 81 44 00 65 00 76 00 50 00 6c 00 61 00 74 00 66 00 6f 00 72 00 6d 00 2e 00 47 00 52 00 2e 00 54 00 69 00 6d 00 65 00 4f 00 66 00 4c 00 61 00 73 00 74 00 44 00 65 00 70 00 6c 00 6f 00 79 00 00 00 02 00 00 00 00 00 02 00 00 00 00 00 02 00 00 00 00 00 01 01 00 01 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 01 d0 fc ea 08 1f 01 00 3b ef a4 c9 4d 2e 36 49 87 59 27 a4 ac d8 b2 41 00 00 01 00 00 00 17 01 00 01 01 00 01 00 00 00 65 00 71 00 0a 00 00 00 00 00 08 76 00 00 00 4c 00 00 81 44 00 65 00 76 00 50 00 6c 00 61 00 74 00 66 00 6f 00 72 00 6d 00 2e 00 47 00 52 00 2e 00 54 00 69 00 6d 00 65 00 4f 00 66 00 4c 00 61 00 73 00 74 00 43 00 6f 00 6e 00 66 00 69 00 67 00 43 00 68 00 61 00 6e 00 67 00 65 00 00 00 02 00 00 00 00 00 02 00 00 00 00 00 02 00 00 00 00 00 01 01 00 01 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 01 50 03 eb 08 20 01 00 02 00 00 00
402026-04-25T21:03:47.656Znmx.enterNmxAdptr.dllCNmxAdapter.TransferData0x8eac738["0x1","0x1","0x1","0x168","0xa041020","0x6d232daa","0x8eb0214","0x8eb0204","0x641add04","0x64"]03600xa04102001 00 3a 01 00 00 00 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 f9 7f 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 02 00 00 30 75 00 00 17 01 00 01 01 00 01 00 00 00 65 00 71 00 0a 00 00 00 00 00 08 6a 00 00 00 40 00 00 81 44 00 65 00 76 00 50 00 6c 00 61 00 74 00 66 00 6f 00 72 00 6d 00 2e 00 47 00 52 00 2e 00 54 00 69 00 6d 00 65 00 4f 00 66 00 4c 00 61 00 73 00 74 00 44 00 65 00 70 00 6c 00 6f 00 79 00 00 00 02 00 00 00 00 00 02 00 00 00 00 00 02 00 00 00 00 00 01 01 00 01 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 01 d0 fc ea 08 1f 01 00 3b ef a4 c9 4d 2e 36 49 87 59 27 a4 ac d8 b2 41 00 00 01 00 00 00 17 01 00 01 01 00 01 00 00 00 65 00 71 00 0a 00 00 00 00 00 08 76 00 00 00 4c 00 00 81 44 00 65 00 76 00 50 00 6c 00 61 00 74 00 66 00 6f 00 72 00 6d 00 2e 00 47 00 52 00 2e 00 54 00 69 00 6d 00 65 00 4f 00 66 00 4c 00 61 00 73 00 74 00 43 00 6f 00 6e 00 66 00 69 00 67 00 43 00 68 00 61 00 6e 00 67 00 65 00 00 00 02 00 00 00 00 00 02 00 00 00 00 00 02 00 00 00 00 00 01 01 00 01 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 01 50 03 eb 08 20 01 00 02 00 00 00
412026-04-25T21:03:47.657Znmx.leaveNmxAdptr.dllCNmxAdapter.TransferData0x0[]
422026-04-25T21:03:47.658Znmx.leaveNmxAdptr.dllCNmxAdapter.PutRequest0x0[]
432026-04-25T21:03:47.672Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x2c2","0x79ab3bc","0x714e980","0x76ffedd8","0x8eac744","0x2c2","0x79ab3bc","0x206","0x3","0x74a421c"]07060x79ab3bcc2 02 00 00 01 00 94 02 00 00 00 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 f9 7f 00 00 02 02 00 00 30 75 00 00 40 1f 50 80 08 a6 00 00 00 40 00 00 91 44 00 65 00 76 00 50 00 6c 00 61 00 74 00 66 00 6f 00 72 00 6d 00 2e 00 47 00 52 00 2e 00 54 00 69 00 6d 00 65 00 4f 00 66 00 4c 00 61 00 73 00 74 00 44 00 65 00 70 00 6c 00 6f 00 79 00 00 00 18 00 00 00 44 00 65 00 76 00 50 00 6c 00 61 00 74 00 66 00 6f 00 72 00 6d 00 00 00 28 00 00 00 47 00 52 00 2e 00 54 00 69 00 6d 00 65 00 4f 00 66 00 4c 00 61 00 73 00 74 00 44 00 65 00 70 00 6c 00 6f 00 79 00 00 00 02 00 00 00 00 00 01 01 00 01 00 01 00 53 f2 9a 00 6a 00 0a 00 5f f1 00 00 01 6c 00 00 00 41 00 6e 00 20 00 69 00 6e 00 74 00 65 00 72 00 6e 00 61 00 6c 00 20 00 65 00 72 00 72 00 6f 00 72 00 20 00 6f 00 63 00 63 00 75 00 72 00 72 00 65 00 64 00 20 00 69 00 6e 00 20 00 74 00 68 00 65 00 20 00 42 00 61 00 73 00 65 00 20 00 52 00 75 00 6e 00 74 00 69 00 6d 00 65 00 20 00 4f 00 62 00 6a 00 65 00 63 00 74 00 00 00 1f 00 00 50 80 01 00 01 00 01 00 30 75 00 00 70 09 d4 92 20 cd b9 4e ae f9 d2 2b ff 0f 00 08 3b ef a4 c9 4d 2e 36 49 87 59 27 a4 ac d8 b2 41 40 1f 50 80 08 be 00 00 00 4c 00 00 91 44 00 65 00 76 00 50 00 6c 00 61 00 74 00 66 00 6f 00 72 00 6d 00 2e 00 47 00 52 00 2e 00 54 00 69 00 6d 00 65 00 4f 00 66 00 4c 00 61 00 73 00 74 00 43 00 6f 00 6e 00 66 00 69 00 67 00 43 00 68 00 61 00 6e 00 67 00 65 00 00 00 18 00 00 00 44 00 65 00 76 00 50 00 6c 00 61 00 74 00 66 00 6f 00 72 00 6d 00 00 00 34 00 00 00 47 00 52 00 2e 00 54 00 69 00 6d 00 65 00 4f 00 66 00 4c 00 61 00 73 00 74 00 43 00 6f 00 6e 00 66 00 69 00 67 00 43 00 68 00 61 00 6e 00 67 00 65 00 00 00 02 00 00 00 00 00 01 01 00 01 00 01 00 53 f2 9a 00 6b 00 0a 00 87 3a 00 00 01 6c 00 00 00 41 00 6e 00 20 00 69 00 6e 00 74 00 65 00 72 00 6e 00 61 00 6c 00 20 00 65 00 72 00 72 00 6f 00 72 00 20 00 6f 00 63 00 63 00 75 00 72 00 72 00 65 00 64 00 20 00 69 00 6e 00 20 00 74 00 68 00 65 00 20 00 42 00 61 00 73 00 65 00 20 00 52 00 75 00 6e 00 74 00 69 00 6d 00 65 00 20 00 4f 00 62 00 6a 00 65 00 63 00 74 00 00 00 20 00 00 50 80 01 00 01 00 01 00
442026-04-25T21:03:47.672Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x2c2","0x79ab3bc","0x714e980","0x76ffedd8","0x8eac744","0x2c2","0x79ab3bc","0x206","0x3","0x74a421c"]15180x3
452026-04-25T21:03:47.672Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x2c2","0x79ab3bc","0x714e980","0x76ffedd8","0x8eac744","0x2c2","0x79ab3bc","0x206","0x3","0x74a421c"]230x74a421c18 7a ad
462026-04-25T21:03:47.674Znmx.leaveNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x0[]
472026-04-25T21:03:47.677Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x97","0xc7661c","0x714e980","0x76ffedd8","0x8eac744","0x97","0xc7661c","0x206","0x3","0x74a421c"]01510xc7661c97 00 00 00 01 00 69 00 00 00 00 00 00 00 4a 23 0c 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 f9 7f 00 00 01 02 00 00 30 75 00 00 32 01 00 02 00 00 00 70 09 d4 92 20 cd b9 4e ae f9 d2 2b ff 0f 00 08 3b ef a4 c9 4d 2e 36 49 87 59 27 a4 ac d8 b2 41 01 00 00 00 03 00 00 00 c0 00 20 2e 5a 46 28 d3 dc 01 06 0a 00 00 00 00 a0 41 c3 55 bd dc 01 00 00 02 00 00 00 03 00 00 00 c0 00 80 18 5b 46 28 d3 dc 01 06 0a 00 00 00 80 c1 75 25 a5 bd
482026-04-25T21:03:47.677Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x97","0xc7661c","0x714e980","0x76ffedd8","0x8eac744","0x97","0xc7661c","0x206","0x3","0x74a421c"]15180x3
492026-04-25T21:03:47.677Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x97","0xc7661c","0x714e980","0x76ffedd8","0x8eac744","0x97","0xc7661c","0x206","0x3","0x74a421c"]230x74a421c18 7a ad
502026-04-25T21:03:47.678Znmx.leaveNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x0[]
512026-04-25T21:03:47.843Znmx.enterNmxAdptr.dllCNmxAdapter.PutRequest0x1["0x8eac738","0x1","0x1","0x1","0x2","0x0","0xad","0x8f8a448","0x5debdc","0x9299463d"]010x2
522026-04-25T21:03:47.843Znmx.enterNmxAdptr.dllCNmxAdapter.PutRequest0x1["0x8eac738","0x1","0x1","0x1","0x2","0x0","0xad","0x8f8a448","0x5debdc","0x9299463d"]11730x8f8a44810 01 00 01 00 00 00 b5 b7 35 ef 41 fe e9 46 97 93 62 43 49 d8 cb f7 ff ff 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 32 00 00 81 54 00 65 00 73 00 74 00 49 00 6e 00 74 00 2e 00 70 00 72 00 6f 00 70 00 65 00 72 00 74 00 79 00 28 00 62 00 75 00 66 00 66 00 65 00 72 00 29 00 00 00 00 00 00 00 00 00 00 00 20 00 00 00 54 00 65 00 73 00 74 00 43 00 68 00 69 00 6c 00 64 00 4f 00 62 00 6a 00 65 00 63 00 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01
532026-04-25T21:03:47.844Znmx.enterNmxAdptr.dllCNmxAdapter.TransferData0x8eac738["0x1","0x1","0x1","0xdb","0xa041020","0x6d232daa","0x8ea77f4","0x8ea77e4","0x641add04","0x64"]02190xa04102001 00 ad 00 00 00 00 00 00 00 02 00 00 00 01 00 00 00 01 00 00 00 f9 7f 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 02 00 00 30 75 00 00 10 01 00 01 00 00 00 b5 b7 35 ef 41 fe e9 46 97 93 62 43 49 d8 cb f7 ff ff 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 32 00 00 81 54 00 65 00 73 00 74 00 49 00 6e 00 74 00 2e 00 70 00 72 00 6f 00 70 00 65 00 72 00 74 00 79 00 28 00 62 00 75 00 66 00 66 00 65 00 72 00 29 00 00 00 00 00 00 00 00 00 00 00 20 00 00 00 54 00 65 00 73 00 74 00 43 00 68 00 69 00 6c 00 64 00 4f 00 62 00 6a 00 65 00 63 00 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01
542026-04-25T21:03:47.845Znmx.leaveNmxAdptr.dllCNmxAdapter.TransferData0x0[]
552026-04-25T21:03:47.846Znmx.leaveNmxAdptr.dllCNmxAdapter.PutRequest0x0[]
562026-04-25T21:03:47.874Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x2e","0xc7aa3c","0x714e980","0x76ffedd8","0x8eac744","0x2e","0xc7aa3c","0x206","0x3","0x74a421c"]0460xc7aa3c2e 00 00 00 01 00 00 00 00 00 00 00 00 00 02 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 f9 7f 00 00 02 02 00 00
572026-04-25T21:03:47.874Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x2e","0xc7aa3c","0x714e980","0x76ffedd8","0x8eac744","0x2e","0xc7aa3c","0x206","0x3","0x74a421c"]15180x3
582026-04-25T21:03:47.874Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0x2e","0xc7aa3c","0x714e980","0x76ffedd8","0x8eac744","0x2e","0xc7aa3c","0x206","0x3","0x74a421c"]230x74a421c18 7a ad
592026-04-25T21:03:47.876Znmx.leaveNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x0[]
602026-04-25T21:03:47.879Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0xd3","0xc7661c","0x714e980","0x76ffedd8","0x8eac744","0xd3","0xc7661c","0x206","0x3","0x74a421c"]02110xc7661cd3 00 00 00 01 00 a5 00 00 00 00 00 00 00 4b 23 0c 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 f9 7f 00 00 01 02 00 00 30 75 00 00 11 01 00 01 00 00 00 b5 b7 35 ef 41 fe e9 46 97 93 62 43 49 d8 cb f7 00 a0 41 c3 55 bd dc 01 80 c1 75 25 a5 bd dc 01 01 08 78 00 00 00 32 00 00 81 54 00 65 00 73 00 74 00 49 00 6e 00 74 00 2e 00 70 00 72 00 6f 00 70 00 65 00 72 00 74 00 79 00 28 00 62 00 75 00 66 00 66 00 65 00 72 00 29 00 00 00 02 00 00 00 00 00 00 00 00 00 20 00 00 00 54 00 65 00 73 00 74 00 43 00 68 00 69 00 6c 00 64 00 4f 00 62 00 6a 00 65 00 63 00 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
612026-04-25T21:03:47.879Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0xd3","0xc7661c","0x714e980","0x76ffedd8","0x8eac744","0xd3","0xc7661c","0x206","0x3","0x74a421c"]15180x3
622026-04-25T21:03:47.879Znmx.enterNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x8eac738["0xd3","0xc7661c","0x714e980","0x76ffedd8","0x8eac744","0xd3","0xc7661c","0x206","0x3","0x74a421c"]230x74a421c18 7a ad
632026-04-25T21:03:47.880Znmx.leaveNmxAdptr.dllCNmxAdapter.ProcessDataReceived0x0[]