Windows-Rootkits/LoadImageCallBack/ReadMe.txt
2016-08-29 12:52:16 +08:00

3 lines
82 B
Plaintext

use PsSetLoadImageNotifyRoutine to monitor dll load
when dll load , scan it's IAT