ReadWriteDriver icon indicating copy to clipboard operation
ReadWriteDriver copied to clipboard

Question regarding detectability

Open zaryar opened this issue 2 years ago • 1 comments

I've been active in the cheating scene for a while now, but this would be my introduction to kernel level cheating. I've already done some research, data pointer hooked functions are mostly detected in the assembly code. Are there any other detection vectors I need to look out for?

zaryar avatar Sep 26 '23 11:09 zaryar

A well hidden data ptr that isnt part of some common table is probably safe. One problem can be stack walking. NMIs can be used to stackwalk for example. Leaving executable memory mapped is also not great.

Ch40zz avatar Sep 29 '23 17:09 Ch40zz