neonprimetime security , just trying to help
Showing posts with label
ntdll
.
Show all posts
Showing posts with label
ntdll
.
Show all posts
Thursday, March 29, 2018
api monitor places to capture unpacked buffer
ntdll.RtlDecompressBuffer (breakpoint AFTER)
_Out_ PUCHAR UncompressedBuffer,
kernel32.WriteProcessMemory (breakpoint BEFORE)
_In_ LPCVOID lpBuffer,
Older Posts
Home
View mobile version
Subscribe to:
Posts (Atom)