Closed memN0ps closed 4 months ago
KernelHook
ntoskrnl.exe
kernel_ept_hook
commands.rs
KernelHooks
HookManager
Mostly helps solves: #20 and #21
SSDT is still needed for syscall hooks, accidentally removed it and currently performing NTOS hooks instead. Both would be nice to have…
KernelHook
struct to track allntoskrnl.exe
function VAs and syscalls.kernel_ept_hook
function.commands.rs
now handles 2 commands, passing them toKernelHooks
which interacts withHookManager
.Mostly helps solves: #20 and #21