
Both, the legacy 'redqueen' trace via libxdc callback as well as new dump_pt trace option are now toggled with aux-buffer trace_mode option. This new qemu cmdline option allows to re-enable the old trace method, or even use both trace methods at the same time.
QEMU-NYX
This repository contains Nyx's fork of QEMU. To enable Hypervisor based snapshots, Intel-PT based tracing, and REDQUEEN style magic byte resolution, we made various extensions to QEMU. This includes the ability to quickly reset memory and devices, obtain precise disassembly of the code running (even when code is partially swapped out / unavailable) & Intel-PT decoding, instrument code running in the VM with breakpoint-based hooks as well as communicating with a fuzzing frontend (e.g. based on libnyx).
You can find more detailed information in our main repository.
Build
./compile_qemu_nyx.sh lto
Bug Reports and Contributions
If you found and fixed a bug on your own: We are very open to patches, please create a pull request!
License
This tool is provided under GPLv2 license.
Free Software Hell Yeah!
Proudly provided by: