Files
wavestone-cdt-edrsandblast/EDRSandblast/Includes/KernelUtils.h
T
Maxime Meignan 7590a11389 CiOptions: Simplifies the way CI.dll base address is recovered
Instead of using the kernel R/W primitive, uses userland API to enumerate
kernel modules
2023-10-09 16:30:36 +02:00

9 lines
355 B
C

#pragma once
#include <Windows.h>
DWORD64 FindNtoskrnlBaseAddress(void);
DWORD64 FindKernelModuleAddressByName(_In_ LPTSTR name);
TCHAR* FindDriverName(DWORD64 address, _Out_opt_ PDWORD64 offset);
TCHAR* FindDriverPath(DWORD64 address);
DWORD64 GetKernelFunctionAddress(LPCSTR function);
TCHAR* FindDriverName(DWORD64 address, _Out_opt_ PDWORD64 offset);