摘要: Windows内核分析索引目录:https://www.cnblogs.com/onetrainee/p/11675224.html KPCR 1. IRQL 2. nt!KeNumberProcessors与nt!KiProcessorBlock 3. KPCR+0x34 KdVersionBlo 阅读全文
posted @ 2020-04-16 19:45 OneTrainee 阅读(1817) 评论(0) 推荐(0)
摘要: Windows内核分析索引目录:https://www.cnblogs.com/onetrainee/p/11675224.html 进程的本质 1. 进程的本质 2. _EPROCESS的重要数据结构 3. 保护进程 4. _PEB+0x10 _RTL_USER_PROCESS_PARAMETER 阅读全文
posted @ 2020-04-16 12:02 OneTrainee 阅读(1322) 评论(0) 推荐(0)