Avast Hooking the Kernel (AV hooks)
Автор: Binary-Win
Загружено: 2025-12-28
Просмотров: 7
We walk through undocumented internals such as CKCL, PerfInfoLogSysCallEntry, HalPrivateDispatch / HalpPerformanceCounter, and explain how ETW can be abused to gain early control over syscall dispatch.
Real-World Example: Avast Kernel Hooks
Avast driver (aswVmm.sys) hook syscalls using this technique Intercepts sensitive operations like:
NtTerminateProcess
NtOpenProcess
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: