开发者

How to track Windows system calls

开发者 https://www.devze.com 2023-02-23 17:45 出处:网络
Is it possible to write a Windows 7 kernel module and create some generic system call filter? Simply, to write some code tha开发者_开发百科t is fired when a system call is made (from any process)?

Is it possible to write a Windows 7 kernel module and create some generic system call filter? Simply, to write some code tha开发者_开发百科t is fired when a system call is made (from any process)?

Thanks James


Here is a great article on hooking Windows API [1]. It is a little old, and not covering Windows 7 kernel. But I think you can still borrow the idea somehow.

0

精彩评论

暂无评论...
验证码 换一张
取 消

关注公众号