搜索资源列表
Miss920
- Miss920程序行为监视器,运用SSDT HOOK技术,可以简单有效的监控程序行为,现在已经实现了进程监控,文件监控,注册表监控,并且可以有效快捷地进行二次开发。-Miss920 monitor program behavior, the use of SSDT HOOK technology, can be simple and effective monitoring of program behavior, the process has already been realized to
BehaviorProMon
- 程序行为监视器,东辉编写,发表在黑客防线,可以监视进程的文件、注册表、驱动等一系列操作。-Monitor program behavior, Donghui prepared and published in hacker defense, you can monitor the process, file, registry, drivers and a series of operations.
RegMon
- 注册表监控驱动程序(以拦截ObReferenceObjectByHandle函数为主)-Registry monitor driver (in order to intercept the main function ObReferenceObjectByHandle)
NT_Driver
- windows 注册表驱动,能监控注册表的一举一动-windows registry drive, can monitor every move of the registry
registry-monitor
- windows注册表监控源码。Ring0级中HOOKSSDT实现。-Windows registry monitoring source. The level Ring0 hook SSDT achieve.