select * from functions where name like '%KERNEL32%' ; attach "mpengine.sqlite" as diff; select count(*) from diff.functions; -- 33614 select count(*) from functions; -- 34146 select f.address ea, f.name name1 from functions f, diff.functions df, (select md_index from diff.functions where md_index != 0 group by md_index having count(*) <= 2 union select md_index from main.functions where md_index != 0 group by md_index having count(*) <= 2 ) shared_mds where f.md_index = df.md_index and df.md_index = shared_mds.md_index and f.nodes > 10 and f.name like 'KERNEL%' ;