NUL0x4C / PerunsFart

replace and unhook ntdll from a suspended process

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Running PerunsFart tech, to patch the hooked ntdll with a ntdll read from a suspended process, thus unhooking ur syscalls.

Reference:

About

replace and unhook ntdll from a suspended process


Languages

Language:C 100.0%