ObOpenObjectByPointer获取进程句柄,获取进程句柄
内核函数:根据进程id获取进程句柄NTSTATUSObOpenObjectByPointer(
IN PVOID Object,
IN ULONG HandleAttributes,
IN PACCESS_STATE PassedAccessState OPTIONAL,
IN ACCESS_MASK DesiredAccess,
IN POBJECT_TYPE ObjectType,
IN KPROCESSOR_MODE AccessMode,
OUT PHANDLE Handle
);
小鱼文聚评论