ECE 4112 Internetwork Security

The figure 10.1 just shows an oldschool SSDT hook of the native function NtQueryDirectoryFile and the figures 10.2 and 10.3 reveal the therewith related hidden processes/files. Figure 10.1: Figure 10.2: … ................
................