Posted: Fri Jan 11, 2013 12:44 am Post subject: Disassembler for drivers (.sys)
OllyDbg can't load up drivers and monitor them. I'm assuming that ovbiously because of the fact that a usermode application can't read a kernel mode driver.
However, is there any software which can view to any degree another driver and monitor api calls?
Joined: 09 May 2003 Posts: 25827 Location: The netherlands
Posted: Fri Jan 11, 2013 4:20 am Post subject:
If it's not a function that runs in a irql level different than passive then you can use cheat engine's kernelmode debugger and enable the global debug function
Then place a breakpoint at the specific address, or setup a luascript that logs all the calls
Tip: If it's an exported api you can use kernel_apiname, else use the driver list and see if you can find the driver and the specific function (or do an aobscan in that region. Make sure kernelmode querrymemoryregions is also enabled) _________________
Do not ask me about online cheats. I don't know any and wont help finding them.
Like my help? Join me on Patreon so i can keep helping
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum