If, say, example.exe, gets the file name of every running process and then opens the file and makes an MD5 hash, it should produce a hash that does not match the normal hash (because the veracrypt container is filled with seemingly random data to other processes). Do I understand correctly on this?
Last edit: Sadrien Hates U 2019-01-06
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
If, say, example.exe, gets the file name of every running process and then opens the file and makes an MD5 hash, it should produce a hash that does not match the normal hash (because the veracrypt container is filled with seemingly random data to other processes). Do I understand correctly on this?
Last edit: Sadrien Hates U 2019-01-06
And if so, why is it that I can successfully decompile a binary in a mounted container with ida-pro.