Windows Kernel Debugging: Processes

How to debug the structures that store information about the process in the Windows operating system? This article will answer that question. You will also be introduced to the methods of manipulating the process. Finally, a method of making an existing process similar to a running instance of another program will be presented, using the notepad process and OneDrive.exe as an example. Prepare tea or coffee and feel free to read!

Aug 7 2020
Tags: windows, kernel debugging, process, forensics, malware, rootkit