Xcon2005_Profiling_Malware_and_Rootkits_from_Ke..
Xcon2005_Profiling_Malware_and_Rootkits_from_Ke..
Xcon2005_Profiling_Malware_and_Rootkits_from_Ke..
- No tags were found...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Better Method…We can replace the callbacks for all object typeswe’re interested inIf we’re interested in finding out every time aprocess or file is opened:Find the FILE_OBJECT object type <strong>and</strong>replace the Open callbackFind the EPROCESS object type <strong>and</strong> replacethe Open callback