You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The handle tab will show zero handles for all processes if you're using the nightly build (or your own builds) and after using the -installkph parameter.
The bug seems to be caused by PhGetHandleInformationEx failing to call NtDuplicateObject when PhKphVerified is FALSE and thus returning STATUS_ACCESS_DENIED and bailing with an empty handleItem->TypeName which then causes the handle tab to show zero handles for all processes.
If PhKphVerified is FALSE then should PH disconnect from KPH so it's able to call the correct APIs (since KPH is unavailable anyway)?
The text was updated successfully, but these errors were encountered:
The handle tab will show zero handles for all processes if you're using the nightly build (or your own builds) and after using the -installkph parameter.
The bug seems to be caused by PhGetHandleInformationEx failing to call NtDuplicateObject when PhKphVerified is FALSE and thus returning STATUS_ACCESS_DENIED and bailing with an empty handleItem->TypeName which then causes the handle tab to show zero handles for all processes.
If PhKphVerified is FALSE then should PH disconnect from KPH so it's able to call the correct APIs (since KPH is unavailable anyway)?
The text was updated successfully, but these errors were encountered: