본문 바로가기

Windows/Kernel

Kernel Callback Functions

 

https://www.n4r1b.com/posts/2020/03/dissecting-the-windows-defender-driver-wdfilter-part-3/

 

Dissecting the Windows Defender Driver - WdFilter (Part 3) :: Up is Down and Black is White — n4r1b

Welcome back to Dissecting the Windows Defender Driver, in the previous part we saw how WdFilter handles the loading of images in memory through an ImageLoad callback routine, we also saw how new threads are checked in two different Thread-creation callbac

www.n4r1b.com

https://m.blog.naver.com/PostView.nhn?blogId=gloryo&logNo=110189963356&proxyReferer=https:%2F%2Fwww.google.com%2F

 

이미지 로드 통지 콜백의 또 다른 버젼? SeRegisterImageVerificationCallback().

오랜만의 포스팅이네요. 한 동안 조~금 바빴네요.. 오늘은 오랜만의 포스팅이니 짧고 간단한걸로 준비했습...

blog.naver.com