搜索资源列表
356
- 内核环境下 一个简单的ssdthook进程名 保护进程 兼容2000以后所有x86系统,可以做为兼容系统的ssdthook参考- 您是不是要找: 内核环境下 一个简单的ssdt hook进程名 保护进程 兼容2000以后所有x86系统,可以做为兼容系统的ssdthook参考 A simple kernel environment protection process ssdthook process name after 2000 all x86 compatible systems t
myhideprocess
- 两种不同方法隐藏进程,一个 SSDT,一个是注入到winlog.exe 希望对大家有帮助-two way hide process windows driver soure code
025890743SSDT-hook
- windows xp ssdt hook学习源码。是一个很不错的简单小程序,有利于理解ssdt hook木马原理。-Windows XP SSDT hook source code to learn. Is a good simple small program, it is helpful to understand the SSDT hook Trojan horse principle.
ssdt
- 采用inline hook高级方式hook所有函数,易语言开发驱动源代码-Advanced mode uses inline hook hook all functions, easy language development driver source code
DxTiTanTools
- C++驱动编程,获取SSDT表,驱动层和应用层的互交-Drive c++ programming, obtain the SSDT table, intercrossing driver layer and application layer
SSDTHook
- it is a ssdt hooking example for requirement, most know ddk.
SDT_UnHook_Code
- 通过读取ntoskrnl.exe文件的导出函数API相对虚拟地址,找到ntoskrnl.exe在内存中的基地址,计算各个API真正的起始地址,比较SSDT表中对应的API地址,不同则去掉SSDT钩子的驱动代码-First,the driver code acquires the RVA of APIs the export table of ntoskrnl.exe.Second,program acquires the base address of ntoskrnl.exe loaded
ssdt_hook_createprocessEx
- 2015年9月,自己编写的SSDT hook! 简单易懂!-September 2015, I have written SSDT hook! Straightforward!
[6-3]Ring3EatIatHook
- Ring 3 的IAT HOOK和 EAT HOOK是一种是一种改函数地址的HOOK法,类似于 SSDT HOOK。-Ring IAT HOOK and EAT HOOK 3 is a function of an address change HOOK law, similar SSDT HOOK.
ssdt
- 驱动内存读写模块源码 可过TP完美运行只支持win32- Drive memory reader module source code can only run over TP perfect support win32
ssdt_hook_ntcreatefile
- SSDTHOOK的源代码,一份SSDTHOOK的入门源代码,方便入门-SSDT HOOK
hookssdt
- 再谈内核及进程保护,利用hook掉系统ssdt保护进程的例子。-Return to the kernel and the process of protection, the use of SSDT hook off system to protect the process of example.
SSDThooksample
- 比较流行的 hook ssdt技术 系统内核钩子-Hook ssdt more popular hook-core technology systems
SSDThooksample
- 比较流行的 hook ssdt技术 系统内核钩子-Hook ssdt more popular hook-core technology systems
HookNtOpenProcess
- 64 位系统 hook ssdt 源码,测试hook的是ntreadvirtualmemory,喜欢就下载吧-64 system SSDT hook source code, test ntreadvirtualmemory is hook, like to download it
HookShadowSSDT
- hook shadow ssdt keylogger - sth like regin code
testKey
- two keylogger source code do ssdt hook
ssdt_hook
- ssdt完整稳定源码,第一个例子HOOK了ZwSetInformationFile保护test.txt文件不被删除 第二个例子HOOK了NtOpenProcess保护PID大于1000的进程不被结束-ssdt complete stable source, ssdt complete stable source, ssdt complete stable source
[3-4]SSDTHookUnhook
- C++下64位系统的HOOK SSDT内核源码 VS2013 wdk8.1编辑-C++ 64-bit system HOOK SSDT kernel source VS2013 wdk8.1 editor
multi
- SSDT恢复源代码,恢复被挂钩的SSDT(系统服务调用函数表)-SSDT recover the source code, recovery by hooking SSDT of (system service call function table)