WIN64驱动编程基础教程

上传者: jxh2003zfr | 上传时间: 2023-02-09 15:18:55 | 文件大小: 13.91MB | 文件类型: ZIP
详细目录如下: 0.基础的基础 |-学习WIN64驱动开发的硬件准备 |-配置驱动开发环境 ------------------------------ 1.驱动级HelloWorld |-配置驱动测试环境 |-编译和加载内核HelloWorld ------------------------------ 2.内核编程基础 |-WIN64内核编程的基本规则 |-驱动程序与应用程序通信 |-内核里使用内存 |-内核里操作字符串 |-内核里操作文件 |-内核里操作注册表 |-内核里操作进线程 |-驱动里的其它常用代码 ------------------------------ 3.内核HOOK与UNHOOK |-系统调用、WOW64与兼容模式 |-编程实现突破WIN7的PatchGuard |-系统服务描述表结构详解 |-SSDT HOOK和UNHOOK |-SHADOW SSDT HOOK和UNHOOK |-INLINE HOOK和UNHOOK ------------------------------ 4.无HOOK监控技术 |-无HOOK监控进线程启动和退出 |-无HOOK监控模块加载 |-无HOOK监控注册表操作 |-无HOOK监控文件操作 |-无HOOK监控进线程句柄操作 |-使用对象回调监视文件访问 |-无HOOK监控网络访问 |-无HOOK监视修改时间 ------------------------------ 5.零散内容 |-驱动里实现内嵌汇编 |-DKOM隐藏进程+保护进程 |-枚举和隐藏内核模块 |-强制结束进程 |-强制读写进程内存 |-枚举消息钩子 |-强制解锁文件 |-初步探索PE32+格式文件 ------------------------------ 6.用户态HOOK与UNHOOK |-RING3注射DLL到系统进程 |-RING3的INLINE HOOK和UNHOOK |-RING3的EAT HOOK和IAT HOOK ------------------------------ 7.反回调 |-枚举与删除创建进线程回调 |-枚举与删除加载映像回调 |-枚举与删除注册表回调 |-枚举与对抗MiniFilter |-枚举与删除对象回调

文件下载

资源详情

[{"title":"( 43 个子文件 13.91MB ) WIN64驱动编程基础教程","children":[{"title":"教程","children":[{"title":"[2-7]内核里操作进程.pdf <span style='color:#111;'> 559.69KB </span>","children":null,"spread":false},{"title":"[5-5]强制读写进程内存.pdf <span style='color:#111;'> 531.36KB </span>","children":null,"spread":false},{"title":"[1-2]编译和测试内核HelloWorld.pdf <span style='color:#111;'> 530.45KB </span>","children":null,"spread":false},{"title":"[2-6]内核里操作注册表.pdf <span style='color:#111;'> 458.85KB </span>","children":null,"spread":false},{"title":"[4-5]无HOOK监控进线程句柄操作.pdf <span style='color:#111;'> 368.09KB </span>","children":null,"spread":false},{"title":"[2-1]WIN64内核编程的基本规则.pdf <span style='color:#111;'> 245.47KB </span>","children":null,"spread":false},{"title":"[5-3]枚举和隐藏内核模块.pdf <span style='color:#111;'> 390.32KB </span>","children":null,"spread":false},{"title":"[4-2]无HOOK监控模块加载.pdf <span style='color:#111;'> 317.21KB </span>","children":null,"spread":false},{"title":"[5-1]驱动里实现内嵌汇编.pdf <span style='color:#111;'> 227.59KB </span>","children":null,"spread":false},{"title":"[3-4]SSDT HOOK和UNHOOK.pdf <span style='color:#111;'> 1.36MB </span>","children":null,"spread":false},{"title":"序:编程本来可以看起来有趣.pdf <span style='color:#111;'> 160.77KB </span>","children":null,"spread":false},{"title":"[3-6]RING0 INLINE HOOK和UNHOOK.pdf <span style='color:#111;'> 502.77KB </span>","children":null,"spread":false},{"title":"[7-5]枚举与对抗MiniFilter.pdf <span style='color:#111;'> 417.72KB </span>","children":null,"spread":false},{"title":"[2-8]内核里其他常用的代码.pdf <span style='color:#111;'> 299.08KB </span>","children":null,"spread":false},{"title":"[5-4]强制结束进程.pdf <span style='color:#111;'> 292.03KB </span>","children":null,"spread":false},{"title":"[4-4]无HOOK监控文件操作.pdf <span style='color:#111;'> 627.60KB </span>","children":null,"spread":false},{"title":"[2-2]驱动程序与应用程序通信.pdf <span style='color:#111;'> 365.45KB </span>","children":null,"spread":false},{"title":"[3-2]编程实现突破WIN7的PatchGuard.pdf <span style='color:#111;'> 372.37KB </span>","children":null,"spread":false},{"title":"[4-6]使用对象回调监视文件访问.pdf <span style='color:#111;'> 349.78KB </span>","children":null,"spread":false},{"title":"[4-1]无HOOK监控进线程启动和退出.pdf <span style='color:#111;'> 544.34KB </span>","children":null,"spread":false},{"title":"[2-4]内核里操作字符串.pdf <span style='color:#111;'> 471.19KB </span>","children":null,"spread":false},{"title":"[5-8]初步探索PE32+格式文件.pdf <span style='color:#111;'> 909.18KB </span>","children":null,"spread":false},{"title":"[5-7]强制解锁文件.pdf <span style='color:#111;'> 168.51KB </span>","children":null,"spread":false},{"title":"[0-1]学习WIN64驱动开发的硬件准备.pdf <span style='color:#111;'> 224.95KB </span>","children":null,"spread":false},{"title":"[6-2]RING3的INLINE HOOK和Anti Hook.pdf <span style='color:#111;'> 750.71KB </span>","children":null,"spread":false},{"title":"[5-2]DKOM隐藏进程+保护进程.pdf <span style='color:#111;'> 416.20KB </span>","children":null,"spread":false},{"title":"[3-3]系统服务描述表结构详解.pdf <span style='color:#111;'> 418.15KB </span>","children":null,"spread":false},{"title":"[0-2]配置驱动开发环境.pdf <span style='color:#111;'> 277.16KB </span>","children":null,"spread":false},{"title":"[4-7]无HOOK监控网络访问.pdf <span style='color:#111;'> 615.97KB </span>","children":null,"spread":false},{"title":"[2-5]内核里操作文件.pdf <span style='color:#111;'> 660.17KB </span>","children":null,"spread":false},{"title":"[5-6]枚举消息钩子.pdf <span style='color:#111;'> 516.95KB </span>","children":null,"spread":false},{"title":"[7-4]枚举与删除对象回调.pdf <span style='color:#111;'> 249.42KB </span>","children":null,"spread":false},{"title":"[4-3]无HOOK监控注册表操作.pdf <span style='color:#111;'> 388.94KB </span>","children":null,"spread":false},{"title":"[4-8]无HOOK监视修改时间.pdf <span style='color:#111;'> 264.82KB </span>","children":null,"spread":false},{"title":"[7-1]枚举与删除进线程回调.pdf <span style='color:#111;'> 298.26KB </span>","children":null,"spread":false},{"title":"[7-3]枚举与删除注册表回调.pdf <span style='color:#111;'> 322.61KB </span>","children":null,"spread":false},{"title":"[7-2]枚举与删除映像回调.pdf <span style='color:#111;'> 202.71KB </span>","children":null,"spread":false},{"title":"[6-3]RING3的IAT HOOK和EAT HOOK.pdf <span style='color:#111;'> 341.99KB </span>","children":null,"spread":false},{"title":"[3-1]系统调用、WOW64与兼容模式.pdf <span style='color:#111;'> 814.13KB </span>","children":null,"spread":false},{"title":"[1-1]配置驱动测试环境.pdf <span style='color:#111;'> 478.87KB </span>","children":null,"spread":false},{"title":"[6-1]RING3注入DLL到系统进程.pdf <span style='color:#111;'> 780.38KB </span>","children":null,"spread":false},{"title":"[3-5]SHADOW SSDT HOOK和UNHOOK.pdf <span style='color:#111;'> 909.67KB </span>","children":null,"spread":false},{"title":"[2-3]内核里使用内存.pdf <span style='color:#111;'> 385.88KB </span>","children":null,"spread":false}],"spread":false}],"spread":true}]

评论信息

免责申明

【只为小站】的资源来自网友分享,仅供学习研究,请务必在下载后24小时内给予删除,不得用于其他任何用途,否则后果自负。基于互联网的特殊性,【只为小站】 无法对用户传输的作品、信息、内容的权属或合法性、合规性、真实性、科学性、完整权、有效性等进行实质审查;无论 【只为小站】 经营者是否已进行审查,用户均应自行承担因其传输的作品、信息、内容而可能或已经产生的侵权或权属纠纷等法律责任。
本站所有资源不代表本站的观点或立场,基于网友分享,根据中国法律《信息网络传播权保护条例》第二十二条之规定,若资源存在侵权或相关问题请联系本站客服人员,zhiweidada#qq.com,请把#换成@,本站将给予最大的支持与配合,做到及时反馈和处理。关于更多版权及免责申明参见 版权及免责申明