Page 1 of 1

How to locate original SSDT

PostPosted:Mon Nov 07, 2011 2:22 pm
by madaboo
Hi,

Assuming that SDT has been hooked e.g for ZwClose.
Is it possible from kernelland to locate original NtClose syscall?
I understand that MmGetSystemRoutineAddress () is not enough here since not all Nt* api calls are exported - is it right?
Thank you

Re: How to locate original SSDT

PostPosted:Mon Nov 07, 2011 5:08 pm
by rkhunter