SSDTHook实现进程保护

上传者: liujiayu2 | 上传时间: 2019-12-21 20:10:13 | 文件大小: 497KB | 文件类型: rar
SSDT 的全称是 System Services Descriptor Table,系统服务描述符表。 这个表就是一个把 Ring3 的 Win32 API 和 Ring0 的内核 API 联系起来。 SSDT 并不仅仅只包含一个庞大的地址索引表,它还包含着一些其它有用的信息,诸如地址索引的基地址、服务函数个数等。 通过修改此表的函数地址可以对常用 Windows 函数及 API 进行 Hook,从而实现对一些关心的系统动作进行过滤、监控的目的。 一些 HIPS、防毒软件、系统监控、注册表监控软件往往会采用此接口来实现自己的监控模块。

文件下载

资源详情

[{"title":"( 35 个子文件 497KB ) SSDTHook实现进程保护","children":[{"title":"SSDTHook","children":[{"title":"SSDTHook.suo <span style='color:#111;'> 18.00KB </span>","children":null,"spread":false},{"title":"SSDTHook","children":[{"title":"stdafx.cpp <span style='color:#111;'> 139B </span>","children":null,"spread":false},{"title":"SSDTHook.vcproj.IEE387O7CCZBQLV.Administrator.user <span style='color:#111;'> 1.39KB </span>","children":null,"spread":false},{"title":"res","children":[{"title":"SSDTHook.ico <span style='color:#111;'> 21.12KB </span>","children":null,"spread":false},{"title":"SSDTHook.rc2 <span style='color:#111;'> 364B </span>","children":null,"spread":false}],"spread":true},{"title":"stdafx.h <span style='color:#111;'> 1.75KB </span>","children":null,"spread":false},{"title":"targetver.h <span style='color:#111;'> 1.01KB </span>","children":null,"spread":false},{"title":"SSDTHook.aps <span style='color:#111;'> 56.62KB </span>","children":null,"spread":false},{"title":"SSDTHook.rc <span style='color:#111;'> 4.53KB </span>","children":null,"spread":false},{"title":"SSDTHook.vcproj <span style='color:#111;'> 5.36KB </span>","children":null,"spread":false},{"title":"SSDTHook.h <span style='color:#111;'> 453B </span>","children":null,"spread":false},{"title":"SSDTHook.cpp <span style='color:#111;'> 1.63KB </span>","children":null,"spread":false},{"title":"resource.h <span style='color:#111;'> 726B </span>","children":null,"spread":false},{"title":"SSDTHookDlg.h <span style='color:#111;'> 2.48KB </span>","children":null,"spread":false},{"title":"SSDTHookDlg.cpp <span style='color:#111;'> 9.74KB </span>","children":null,"spread":false},{"title":"ReadMe.txt <span style='color:#111;'> 2.72KB </span>","children":null,"spread":false}],"spread":false},{"title":"SSDTHook.sln <span style='color:#111;'> 890B </span>","children":null,"spread":false},{"title":"HookDriver","children":[{"title":"HookDriver.ncb <span style='color:#111;'> 339.00KB </span>","children":null,"spread":false},{"title":"HookDriver.suo <span style='color:#111;'> 11.50KB </span>","children":null,"spread":false},{"title":"HookDriver.sln <span style='color:#111;'> 2.47KB </span>","children":null,"spread":false},{"title":"HookDriver","children":[{"title":"HookDriver.vsprops <span style='color:#111;'> 289B </span>","children":null,"spread":false},{"title":"ddkprebld.cmd <span style='color:#111;'> 70B </span>","children":null,"spread":false},{"title":"BuildLog.htm <span style='color:#111;'> 15.35KB </span>","children":null,"spread":false},{"title":"HookDriver.WXP.vcproj.IEE387O7CCZBQLV.Administrator.user <span style='color:#111;'> 3.84KB </span>","children":null,"spread":false},{"title":"ddkpostbld.cmd <span style='color:#111;'> 222B </span>","children":null,"spread":false},{"title":"HookDriver.WXP.vcproj <span style='color:#111;'> 4.68KB </span>","children":null,"spread":false},{"title":"makefile <span style='color:#111;'> 261B </span>","children":null,"spread":false},{"title":"SSDTHook.h <span style='color:#111;'> 9.94KB </span>","children":null,"spread":false},{"title":"VisualDDKHelpers.h <span style='color:#111;'> 1.03KB </span>","children":null,"spread":false},{"title":"SSDTHook.cpp <span style='color:#111;'> 11.59KB </span>","children":null,"spread":false},{"title":"ddkbldenv.cmd <span style='color:#111;'> 20B </span>","children":null,"spread":false},{"title":"sources <span style='color:#111;'> 212B </span>","children":null,"spread":false}],"spread":false}],"spread":true}],"spread":true},{"title":"驱动加载工具.rar <span style='color:#111;'> 329.44KB </span>","children":null,"spread":false},{"title":"测试程序及驱动","children":[{"title":"SSDTHook.exe <span style='color:#111;'> 46.50KB </span>","children":null,"spread":false},{"title":"SSDT_Hook.sys <span style='color:#111;'> 16.38KB </span>","children":null,"spread":false}],"spread":true}],"spread":true}]

评论信息

免责申明

【只为小站】的资源来自网友分享,仅供学习研究,请务必在下载后24小时内给予删除,不得用于其他任何用途,否则后果自负。基于互联网的特殊性,【只为小站】 无法对用户传输的作品、信息、内容的权属或合法性、合规性、真实性、科学性、完整权、有效性等进行实质审查;无论 【只为小站】 经营者是否已进行审查,用户均应自行承担因其传输的作品、信息、内容而可能或已经产生的侵权或权属纠纷等法律责任。
本站所有资源不代表本站的观点或立场,基于网友分享,根据中国法律《信息网络传播权保护条例》第二十二条之规定,若资源存在侵权或相关问题请联系本站客服人员,zhiweidada#qq.com,请把#换成@,本站将给予最大的支持与配合,做到及时反馈和处理。关于更多版权及免责申明参见 版权及免责申明