Windows-Rootkits/ProcessCreateCallBack
2016-08-29 15:14:42 +08:00
..
ProcessManager Add files via upload 2016-08-29 15:05:51 +08:00
ProcessManagerRing0 Add files via upload 2016-08-29 15:10:23 +08:00
ProcessManager.sln Add files via upload 2016-08-29 15:06:43 +08:00
ProcessManager.suo Add files via upload 2016-08-29 15:06:43 +08:00
ReadMe.txt Create ReadMe.txt 2016-08-29 15:14:42 +08:00

1.Enum Process By PsLookupProcessByProcessId/travel Active List/PspCidTable
2.Hdie Process By Process Active List/PspCidTable
3.Monitor Process CreateInformation By PsSetCreateProcessNotifyRoutineEx