12.07.2015 Views

Xcon2005_Profiling_Malware_and_Rootkits_from_Ke..

Xcon2005_Profiling_Malware_and_Rootkits_from_Ke..

Xcon2005_Profiling_Malware_and_Rootkits_from_Ke..

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Better Method…We can replace the callbacks for all object typeswe’re interested inIf we’re interested in finding out every time aprocess or file is opened:Find the FILE_OBJECT object type <strong>and</strong>replace the Open callbackFind the EPROCESS object type <strong>and</strong> replacethe Open callback

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!