You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Sorry there's no alternative at the moment to get the object address. This feature is a new change in 24H2 where kernel addresses are not returned unless the caller is running with SeDebugPrivilege.
新版本获取句柄对象的时候会先通过
ExIsRestrictedCaller
判断是否存在SeDebugPrivilege
权限,在ObpCaptureHandleInformation
函数的时候只有满足权限才会赋值给handle_table的Object,在线版本中是否已经有了新的替代方案?The text was updated successfully, but these errors were encountered: