Skip to content

This driver will hook the ZwEnumerateValueKey on 32 bit windows systems by hooking the function through the SSDT table. The malicious hook will hide registry keys with a name that contains "_root_"

Notifications You must be signed in to change notification settings

Marsh61/Windows-Driver-Hook-ZwEnumerateValueKey

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 

About

This driver will hook the ZwEnumerateValueKey on 32 bit windows systems by hooking the function through the SSDT table. The malicious hook will hide registry keys with a name that contains "_root_"

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages