Extracting the SSDT directly from ntoskrnl.exe
For any developers wanting to make their apps hard to hook and analyze, making direct syscalls to the kernel is a useful approach to look into. There are countless resources for making this happen, from j00ru's work building a full table, to the lib...
lodsb.com7 min read