Quantcast
Channel: 看雪安全论坛
Viewing all articles
Browse latest Browse all 9556

【求助】HOOK NtCreateProcessEx 怎么输出文件信息

$
0
0
小菜在HOOK NtCreateProcessEx 函数时希望得到 文件名 但不知道怎么写
HOOK NtCreateProcessEx 之后 创建进程
想要输出 文件的信息 希望大神回答


在下面这个自定义的函数中 输出文件信息
NTSTATUS
MyNtCreateProcessEx(
__out PHANDLE ProcessHandle,
__in ACCESS_MASK DesiredAccess,
__in_opt POBJECT_ATTRIBUTES ObjectAttributes,
__in HANDLE ParentProcess,
__in ULONG Flags,
__in_opt HANDLE SectionHandle,
__in_opt HANDLE DebugPort,
__in_opt HANDLE ExceptionPort,
__in ULONG JobMemberLevel
)
{
NTSTATUS status = STATUS_SUCCESS;

KdPrint(("ENTER mY cREATEprocess \n \r"));


UN_PROTECT();
RtlCopyMemory((PVOID)OldNtCreateProcessEx,(CONST PVOID)bOldBytes,5);
RE_PROTECT();

status = OldNtCreateProcessEx( ProcessHandle,
DesiredAccess,
ObjectAttributes,
ParentProcess,
Flags,
SectionHandle,
DebugPort,
ExceptionPort,
JobMemberLevel);
UN_PROTECT();
RtlCopyMemory((PVOID)OldNtCreateProcessEx,(CONST PVOID)bNewBytes,5);
RE_PROTECT();

return status;

}

Viewing all articles
Browse latest Browse all 9556

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>