neonprimetime security , just trying to help
Thursday, March 29, 2018
api monitor places to capture unpacked buffer
ntdll.RtlDecompressBuffer (breakpoint AFTER)
_Out_ PUCHAR UncompressedBuffer,
kernel32.WriteProcessMemory (breakpoint BEFORE)
_In_ LPCVOID lpBuffer,
No comments:
Post a Comment
Newer Post
Older Post
Home
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment