Windows-Rootkits/LoadImageCallBack/ReadMe.txt

3 lines
82 B
Plaintext
Raw Normal View History

2016-08-29 04:52:16 +00:00
use PsSetLoadImageNotifyRoutine to monitor dll load
when dll load , scan it's IAT