I trace the userdump in NTDDK.It using RtlImageNtHeader to search the NTOSKRNL spaces, to find its export functions.Does anyone know another...
全文
回复(1) 2002-08-13 09:45 来自版块 - 内核编程
表情
lyabcdNT Kernel level hooking There are several methods for achieving hooking of NT system services in kernel mode. The most popular interception...(2002-08-13 10:11)

返回顶部