mirror of
https://github.com/wavestone-cdt/EDRSandblast.git
synced 2026-06-10 17:31:23 +00:00
Userland hooks: ignore api-ms-* DLLs
This commit is contained in:
@@ -426,6 +426,9 @@ _Ret_notnull_ HOOK* searchHooks(const char* csvFileName) {
|
|||||||
if (dll_name.Buffer == NULL) {
|
if (dll_name.Buffer == NULL) {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
if (!_wcsnicmp(dll_name.Buffer, L"api-ms", 6)) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
WCHAR* moduleName = currentModuleEntry->FullDllName.Buffer;
|
WCHAR* moduleName = currentModuleEntry->FullDllName.Buffer;
|
||||||
|
|
||||||
if (!hooksFoundInLastModule) {
|
if (!hooksFoundInLastModule) {
|
||||||
|
|||||||
Reference in New Issue
Block a user