Closed bill-e-ghote closed 2 years ago
Firstly you have to load the driver into the kernel then run cdbg.exe
Got it. Thanks.
Firstly you have to load the driver into the kernel then run cdbg.exe
I have the same question, I know I need to load driver into the kernel but I do not know what tools can I use to do it.
@river7816 You can learn from this link: https://www.ired.team/miscellaneous-reversing-forensics/windows-kernel-internals/loading-a-windows-kernel-driver-osr-driver-loader-debugging-with-source-code
Or use new Black Angel Rootkit which can be loaded with kdmapper
Not sure if my error or the application. Please advise.