During the course of windows internal, I wonder how we can do a live response on the kernel level. I start with a small trick to print the SSDT functions, the code have been modified and collected from different resources. I don't remember them, but thanks for all open source communities :) the code based on MemProcFS ; https://github.com/ufrisk/MemProcFS
-
Notifications
You must be signed in to change notification settings - Fork 2
H4Security/SSDTFinder
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
No description, website, or topics provided.
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published