Perfect Windows Kernel Hooking

I've read somewhere ia_32_sysenter holds the offset which is loaded into EIP when sysenter is executed, is there any kind of stealth,best method of kernelhooking when the purpose is monitoring the value of EAX when sysenter is called?

Re: Malware analysis - Buster Sandbox Analyzer

buster, my .exe calls writeprocessmemory 4 times, your tool only shows it is called 1 time, is it normal?

Re: Malware analysis - Buster Sandbox Analyzer

hey buster, congratz, nice tool, i'd like to know what type of hook you use to monitor the programs?

Re: Device Driver Development for Beginners - Reloaded

can you guys please tell me where i can find this book in pdf?

"Windows NT Device Driver Development (OSR Classic Reprints)" ?

Re: hide idt-hooking

that's a really nice code thanks for sharing :)

Re: Kill kaspersky 2012 from user mode :)

great, any other av's vulnerable to this attack vector?

what about sharing with us a poc? :)

about ring3 hook

Hi, Sorry if this is a too much noob question, but i've hooked a function in another process successfully with dll injection, no problem 'til now, but what if i want to create a window into the hooked process, pause the execution flow, and wait for the user to put something in a textbox and click a ...

Re: Process list without process32next()

thanks guys, very interesting how the most of api's exported by ntdll.dll got the Zw prefix instead of Nt hehe :)

the program was calling enumprocess from psapi

Process list without process32next()

Hello guys, i'm reversing a software which is listing all processes without calling process32next() and it's in usermode, is there really any other way to do it?

Re: Find what terminated your process..

thanks, procmon gives me 2 (thread exit) the first one is weird and the call comes from ntdll.dll the second one is interesting : CALL DWORD PTR DS:[<&KERNEL32.GetQueuedC>; kernel32.GetQueuedCompletionStatus from xul.dll, it's a firefox plugin i'm reversing and i want to prevent plugin-container.exe...