Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

新版本无法获取到内核地址,是否现在有了新的替代 #3

Open
Wker666 opened this issue Nov 12, 2024 · 1 comment
Open

Comments

@Wker666
Copy link

Wker666 commented Nov 12, 2024

新版本获取句柄对象的时候会先通过 ExIsRestrictedCaller 判断是否存在 SeDebugPrivilege 权限,在 ObpCaptureHandleInformation 函数的时候只有满足权限才会赋值给handle_table的Object,在线版本中是否已经有了新的替代方案?

@yardenshafir
Copy link
Owner

Sorry there's no alternative at the moment to get the object address. This feature is a new change in 24H2 where kernel addresses are not returned unless the caller is running with SeDebugPrivilege.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants