Hi, I haven't started researching as yet or debugging however there seems to be a different way in which 8.1/10 can query a process protected via obRegisterCallbacks or a module hidden from VAD. Process Hacker is one tool that seems to be able to query process/module on 8.1/10 only (x64) even when the driver is disabled...
Has anyone noticed this change, is it an operating system change or something different? I will post any finding I get.
thanks
Has anyone noticed this change, is it an operating system change or something different? I will post any finding I get.
thanks