wincheck
http://redplait.blogspot.com/search/label/wincheckDownload mirror
Changelog:
[*]add dumping some internals of ci.dll (like g_CiOptions & g_CiKernelApis). Thanks to Alex Ionescu for this idea
[*]add dumping of BootEnvironmentInformation (5th dword from ExpBootEnvironmentInformation used in many interesting functions like SepIsMinTCB, he-he)
[*]add dumping of EPROCESS.SignatureLevel &EPROCESS.SectionSignatureLevel (w8 only)
[*]some bugs where fixed
MJ:俄罗斯人搞得一个类似ARK的Windows内部结构分析工具wincheck,应该是目前最全的了 谢谢楼主分享 NB,谢谢楼主 谢谢楼主,顶mj{:1_912:} Nice tool. Thank you. zhege是什么东西 恩 昨天正在研究一个APK 爆顶一下,回去用用{:1_912:} 不错'看看好不好 俄罗斯人怎么这么聪明,{:301_999:}
页:
[1]
2