搜索资源列表
KernelLookup
- Open Source SSDT Hook detection utility, it will scan the SSDT Entries in the kernel (ntoskrnl.exe) and find the functions that are hooked & not in the kernel base address range .
neihe
- 获取内核ntoskrnl.exe基地址的几种常见办法-Access to the kernel ntoskrnl.exe base address several common approaches