Closed ghost closed 1 year ago
Interrutor use only instruction level hooking. There is only two features temporary based on function hooking : followingThread
depending on libc, and startOnLoad
depending on linker64.
Interruptor uses following strategy :
How is SVC / syscall hooking is implemented?
If someone tries to bypass Frida by using syscalls directly without libc wrapper will we detect them? For example some packers do that