I want to print IAT information of kernel module.
Sometimes, DataDir[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress is not a valid address (MmIsAddressValid return FALSE).
For example, DataDir[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress of NTOSKRNL is not valid.
But PCHunter32.exe can find out the IAT HOOK of NTOSKRNL.
Could someone tell me how to do that?
Sometimes, DataDir[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress is not a valid address (MmIsAddressValid return FALSE).
For example, DataDir[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress of NTOSKRNL is not valid.
But PCHunter32.exe can find out the IAT HOOK of NTOSKRNL.
Could someone tell me how to do that?