SetDispositionInformationEx
Flags: FILE_DISPOSITION_DELETE, FILE_DISPOSITION_POSIX_SEMANTICS
CreateFile
Desired Access: Delete, Disposition: Open, Options: Non-Directory File, Delete On Close, Attributes: n/a, ShareMode: Delete, AllocationSize: n/a, OpenResult: Opened
'Windows > Kernel' 카테고리의 다른 글
FltGetFileNameInformation FLT_FILE_NAME_NORMALIZED (1) | 2021.06.23 |
---|---|
Registry / OB filtering (0) | 2021.04.09 |
Create process from kernel mode (0) | 2021.02.15 |
DNS 쿼리 탐지 및 변조 (0) | 2021.01.18 |
FltQueryInformationFile - TopLevel IRP 인 경우 호출 불가 (0) | 2020.11.27 |