Closed Turbo-Thorschten closed 4 years ago
I'm trying to hexdump another process and I don't really know how to find the mapped regions of the target process. Do you have any idea if theres already a relatively simple method to do that?
Best regards!
Well, you can use the KbExecuteShellCode to use a kernel-level ZwQueryVirtualMemory with a kernel handle of the target process.
I'm trying to hexdump another process and I don't really know how to find the mapped regions of the target process. Do you have any idea if theres already a relatively simple method to do that?
Best regards!