gpt4 book ai didi

c - 如何检测访问指定注册表的进程名称(如进程监视器)

转载 作者:行者123 更新时间:2023-11-30 20:30:33 24 4
gpt4 key购买 nike

enter image description here

如何像进程监视器一样检测访问指定注册表的进程名?

较旧的 regmon 使用 SSDT Hooking 来实现,但在 Windows 10 中,我们无法进行 hook使用它的注册表。 SSDT Hooking seem to be legacy technology

SSDT Hooking 有替代品吗?

最佳答案

您应该实现适当的 registry filtering driver .

A registry filtering driver is any kernel-mode driver that filters registry calls, such as the driver component of an antivirus software package. The configuration manager, which implements the registry, allows registry filtering drivers to filter any thread's calls to registry functions.

关于c - 如何检测访问指定注册表的进程名称(如进程监视器),我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/54053535/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com