Hi,
Any ideas how to obtain SYSENTER_EIP_MSR (unexported nt!kiFastCallEntry) in kernel module?
Only way I see is to attach to user process, call any zw api then get call stack and tkae address of kitrap - however I'm not sure if it can work?
Any ideas guys?
Thanks!
Any ideas how to obtain SYSENTER_EIP_MSR (unexported nt!kiFastCallEntry) in kernel module?
Only way I see is to attach to user process, call any zw api then get call stack and tkae address of kitrap - however I'm not sure if it can work?
Any ideas guys?
Thanks!