13 Security Lab

Windows API - User mode matched kernel mode 본문

Computer Science/Windows Externals

Windows API - User mode matched kernel mode

Maj0r Tom 2015. 5. 1. 18:37
Processes User mode Kernel mode
NtTerminateProcess PsTerminateProcess/PspTerminateProcess
NtOpenProcess PsLookupProcessByProcessId,
ObOpenObjectByPointer
Threads User mode Kernel mode
NtTerminateThread PspTerminateThreadByPointer
NtOpenThread PsLookupThreadByThreadId,
ObOpenObjectByPointer
NtGetContextThread PsGetContextThread
NtSetContextThread PsSetContextThread
Virtual memory User mode Kernel mode
NtProtectVirtualMemory MiProtectVirtualMemory
NtReadVirtualMemory MmCopyVirtualMemory
NtWriteVirtualMemory MmCopyVirtualMemory
File system User mode Kernel mode
NtCreateFile IoCreateFile
NtDeviceIoControlFile
/NtFsControlFile
IopXxxControlFile
Objects User mode Kernel mode
NtClose ObCloseHandle/ObpCloseHandle
NtDuplicateObject ObDuplicateObject
NtQueryObject ObQueryNameString
System call User mode Kernel mode
KiIntSystemCall KiSystemService
KiFastSystemCall KiFastCallEntry


Comments