A forum for reverse engineering, OS internals and malware analysis 

 #27571  by kz丶cn
 Thu Jan 07, 2016 5:05 am
hello! kernelmode!
My English is not very good, don't suggest. :roll:
Although through ZwQuerySystemInformation Can get all the handle.
But I want to know some of the original rational things.
I have two questions...
Question 1:Just like the title.
Question 2:Like I'm getting a handle is a file object,After the _OBJECT_HEADER is the body ,The body is _FILE_OBJECT.
That if I got the KEY、Mutant object handle ,After the _OBJECT_HEADER followed by what is structure? like _KEY_OBJECT 、_MUTANT_OBJECT But there is no this structure.
What is the structure, which can be all?
Thank!
I am a novice, don't scold me...