![]() |
|
#11
|
|||
|
|||
|
Win10 has more surprises to offer:
https://ntquery.wordpress.com/2015/09/07/windows-10-new-anti-debug-outputdebugstringw/ I also see some weird behavior of NtQueryInformationProcess. You can query ProcessBasicInformation with different buffer sizes. size = 24 -> normal behavior, expected size like in all windows editions size = 32 -> extended information? You can get more information...
__________________
My blog: https://ntquery.wordpress.com |
| The Following User Gave Reputation+1 to Carbon For This Useful Post: | ||
Loki (09-08-2015) | ||
| The Following 4 Users Say Thank You to Carbon For This Useful Post: | ||
besoeso (09-08-2015), elephant (11-15-2015), Loki (09-08-2015), Storm Shadow (12-11-2015) | ||
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| ScyllaHide HookLibraryx86.dll | phroyt | General Discussion | 3 | 10-25-2019 09:48 |
| ScyllaHide Detector | Lueilwitz | Source Code | 2 | 08-07-2019 06:32 |