Windows-Rootkits/LoadImageCallBack
2016-08-29 12:57:37 +08:00
..
Dll Add files via upload 2016-08-29 12:56:14 +08:00
inject Add files via upload 2016-08-29 12:57:37 +08:00
ReadMe.txt Create ReadMe.txt 2016-08-29 12:52:16 +08:00

use PsSetLoadImageNotifyRoutine to monitor dll load
when dll load , scan it's IAT