hook

#define SYSTEMSERVICE(_function) \ KeServiceDescriptorTable.ServiceTableBase[ \   *(PULONG)((PUCHAR)_function+1)] //1.加载/ 解除SSDT挂钩系统服务函数ZwXXX NTSTATUS mySSDTHook(IN BOOLEAN bAdd) { If(bAdd)//开始挂钩
相关文章
相关标签/搜索