Skip to content

Cisco-Talos/Windows-drivers-GDT-file

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 

Repository files navigation

Windows-drivers-GDT-file

The following functions are included in this data type archive:

CmRegisterCallbackEx
ExfAcquirePushLockExclusive
ExfReleasePushLockExclusive
IoCreateDriver
IoQueryFileDosDeviceName
KeInitializeApc
KeInsertQueueApc
KeReleaseQueuedSpinLock
KeStackAttachProcess
KeUnstackDetachProcess
MmFlushImageSection
NdisAllocateGenericObject
NdisGetDataBuffer
ObCreateObject
ObOpenObjectByName
ObOpenObjectByPointer
ObQueryNameString
ObReferenceObjectByName
PsLookupProcessByProcessId
PsLookupProcessThreadByCid
PsLookupThreadByThreadId
RtlAbsoluteToSelfRelativeSD
RtlAddAccessAllowedAce
RtlCaptureStackBackTrace
RtlGetDaclSecurityDescriptor
RtlGetGroupSecurityDescriptor
RtlGetOwnerSecurityDescriptor
RtlGetSaclSecurityDescriptor
RtlLengthSid
RtlRandomEx
SeCaptureSecurityDescriptor
SeCreateAccessState
SeDeleteAccessState
SeDeleteObjectAuditAlarm
SeTokenIsAdmin
ZwDuplicateObject
ZwFlushBuffersFile
ZwOpenDirectoryObject
ZwOpenProcessTokenEx
ZwOpenThreadTokenEx
ZwQueryDirectoryObject
ZwQueryInformationProcess
ZwQueryInformationToken
ZwQuerySystemInformation
ZwRenameKey
ZwSaveKey
ZwSetInformationObject
ZwSetSecurityObject
ZwWaitForSingleObject

About

Ghidra data type archive for Windows driver analysis

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published