ninetails0 / Detect-HiddenThread-via-KPRCB

Detect removed thread from PspCidTable.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Detect-HiddenThread-via-KPRCB

Detect removed thread from PspCidTable.

Going through the system threads through the KPRCB structures, we can easily determine which of these threads is missing in the cid table, checking whether the thread is in the cid table or not is carried out using the "PsLookupThreadByThreadId" function.

This system does not check the main sheet with threads, you can also iterate through the main table and compare it with the KPRCB table.

About

Detect removed thread from PspCidTable.


Languages

Language:C 66.2%Language:C++ 33.8%