A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #24744  by binstory1523
 Thu Dec 25, 2014 2:01 pm
Hi, try to ask a question
As the Force Suspend Process method Force ReadProcessMomey think you will also like
Have you ever seen something like this Do you minutes or materials similar examples?
Should some of the open source even possible?
 #24747  by EP_X0FF
 Thu Dec 25, 2014 3:27 pm
Where? In user or in kernel mode?
 #24755  by EP_X0FF
 Fri Dec 26, 2014 7:40 am
binstory1523 wrote:
EP_X0FF wrote:Where? In user or in kernel mode?
Yes, In user or in kernel mode there a way?
Yes you can.

In user mode use direct syscall to NtReadVirtualMemory,e g.g http://www.kernelmode.info/forum/viewto ... 575&p=4187
In kernel mode google for KeStackAttackProcess and MDLs.