能力值:
( LV2,RANK:10 )
|
-
-
2 楼
示例1:进程
PEPROCESS pEprocess = NULL;
ObReferenceObjectByHandle(ProcessHandle, FILE_READ_DATA, *PsProcessType, KernelMode,
(PVOID*)&pEprocess, NULL);
示例2:线程
PETHREAD pEthread = NULL;
ObReferenceObjectByHandle(ThreadHandle, 0, *PsThreadType, KernelMode,
(PVOID*)&pEthread, NULL);
最后于 2021-1-21 15:56
被ybt编辑
,原因:
|
能力值:
( LV1,RANK:0 )
|
-
-
3 楼
谢谢
|
|
|