Skip to content
This repository has been archived by the owner on Aug 14, 2023. It is now read-only.

ProcessDebugObjectHandleFlag

Мрак edited this page Jun 12, 2022 · 1 revision

How it works

When debugging begins, a kernel object called “debug object” is created. It is possible to query for the value of this handle by using the undocumented ProcessDebugObjectHandle (0x1e) class.

Reference

Anti-Debug Tricks

Clone this wiki locally