Skip to content

内核中先加载驱动目录下的ntdll动态链接库,然后通过名称在ntdll中找到函数序号,通过序号到SSDT中找到函数地址。

Notifications You must be signed in to change notification settings

Ricardo-Tu/KernelGetFunctionAddressFromSSDT

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 
 
 

Repository files navigation

KernelGetFunctionAddressFromSSDT

内核中先加载驱动目录下的ntdll动态链接库,然后通过名称在ntdll中找到函数序号,通过序号到SSDT中找到函数地址。

About

内核中先加载驱动目录下的ntdll动态链接库,然后通过名称在ntdll中找到函数序号,通过序号到SSDT中找到函数地址。

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages