内核中先加载驱动目录下的ntdll动态链接库,然后通过名称在ntdll中找到函数序号,通过序号到SSDT中找到函数地址。
-
Notifications
You must be signed in to change notification settings - Fork 0
Ricardo-Tu/KernelGetFunctionAddressFromSSDT
About
内核中先加载驱动目录下的ntdll动态链接库,然后通过名称在ntdll中找到函数序号,通过序号到SSDT中找到函数地址。
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published