A forum for reverse engineering, OS internals and malware analysis 

Forum for discussion about kernel-mode development.
 #12378  by flauteABC
 Wed Mar 28, 2012 11:09 am
We need a driver for 32 and x64 bit Windows XP and W7 with the following requirements:

- Sets the BTF flag (MSR_DEBUGCTLA) for specific processes (configurable)
- Hooks int1 and catches, handles the single steps on branches
- Inside the int1 handler: for all CTI instructions which modify the stack, the stack values are extracted and logged to disk

Payment: ~400-600€, Paypal.

Send me a message if you are interested.

-- FlauteABC