CRACKL@B Оригинальный DVD-ROM крэкера: CRACKL@B DVD !
Домой | Статьи | RAR-cтатьи | Форум | Программирование | Скачать | DVD-ROM
Новичку | FAQ | Ссылки | Интервью | Архив | Новости | Связь


Русский / Russian English / Английский

Сейчас на форуме: huckfuck, RioTiZ, tempread, tihiy_grom (+7 невидимых пользователей)
 · Начало · Статистика · Регистрация · Поиск · ПРАВИЛА ФОРУМА · Язык · RSS ·

 CRACKL@B —› Софт, варез —› Kernel Detective, new security & analysis tool
Посл.ответ Сообщение
pavka

Ранг: 994.0 (! ! !)
Статус: Участник

Создано: 3 сентября 2008 07:39:37
Личное сообщение #1

Kernel Detective is a free tool that help you detect, analyze, manually modify and fix some Windows NT kernel modifications. Kernel Detective gives you the access to the kernel directly so it's not oriented for newbies. Changing essential kernel-mode objects without enough knowledge will lead you to only one result, BSOD

Everything is done from kernel-mode.

With Kernel Detective you can:

Enumerate running processes and print important values like Process Id, Parent Process Id, ImageBase, EntryPoint, VirtualSize, PEB block address and EPROCESS block address. Kernel Detective also has special scan methods for detecting hidden processes

Enumerate a specific running processe Dynamic-Link Libraries. Also show every Dll ImageBase, EntryPoint, Size and Path .

Enumerate loaded kernel-mode drivers and show every driver ImageBase, EntryPoint, Size, Name and Path. Also it has special methods for detecting hidden drivers.

Scan the system service table (SSDT) and show every service function address and the real function address. You can restore single service function address or restore the whole table.

Scan the shadow system service table (Shadow SSDT) and show every shadow service function address and the real function address. You can restore single shadow service function address or restore the whole table

Scan the interrupts table (IDT) and show every interrupt handler offset, selector, type, Attributes and real handler offset. This is applied to every processor in a multi-processors machines.

Scan the important system kernel modules, detect the modifications in it's body and analyze it. For now it can detect and restore inline code modifications, EAT and IAT hooks. I'm looking for more other types of hooks next releases of Kernel Detective.

A nice disassembler rely on OllyDbg disasm engine, thanks Oleh Yuschuk for publishing the source code of your nice disasm engine . With it you can disassemble, assemble and hex edit virtual memory of a specific process or even the kernel space memory. Kernel Detective use it's own Read/Write routines from kernel-mode and doesn't rely on any windows API. That make Kernel Detective able to R/W processes VM even if NtReadProcessMemory/NtWriteProcessMemory is hooked, also bypass the hooks on other kernel-mode important routines like KeStackAttachProcess and KeAttachProcess

Show the messages sent by drivers to the kernel debugger just like Dbgview by Mark Russinovich. It's doing this by hooking interrupt 0x2d wich is responsible for outputing debug messages. Hooking interrupts may cause problems on some machines so DebugView is turned off by default, to turn it on you must run Kernel Detective with "-debugv" parameter.

http://www.at4re.com/tools/Releases/GamingMasteR/Kernel_Detective_v1.0 .zip
LazzY

Ранг: 107.9 (ветеран)
Статус: Участник

Создано: 4 сентября 2008 09:39:32
Личное сообщение #2

bsodogenerator
Dr3d

Ранг: 47.7 (посетитель)
Статус: Участник

Создано: 4 сентября 2008 11:57:23
Личное сообщение #3

pavka пишет:
it's not oriented for newbies

Прога прикольная, но далеко не всем нужная.
pavka

Ранг: 994.0 (! ! !)
Статус: Участник

Создано: 4 сентября 2008 13:21:16
Личное сообщение #4

LazzY пишет:
bsodogenerator

Dr3d пишет:
Прога прикольная, но далеко не всем нужная.


deroko Sep 2 2008, 05:37 PM
Post #8
[EXT]

Group: ARTeam
Posts: 1,741
Joined: 14-May 05
Member No.: 1,408
very handy tool, tnx for sharing
В общем без коментов ;)
ясен пень кому и кобыла невеста...
Av0id

Ранг: 387.6 (мудрец)
Статус: Участник

Создано: 4 сентября 2008 14:54:14
Личное сообщение #5

заколебали уже одно и тоже переписывать, пора бы уже давно под x64 начать писать
=TS=


Ранг: 213.0 (наставник)
Статус: Участник
# Malware KilleR #

Создано: 4 сентября 2008 16:30:25
Личное сообщение #6

Хм, и к сожалению под Windows 2003 SP2 не работает

-----
DREAMS CALL US
 CRACKL@B —› Софт, варез —› Kernel Detective, new security & analysis tool
    Для печати 


Оригинальный DVD-ROM крэкера: CRACKL@B DVD !


Вы находитесь на форуме сайта CRACKLAB.RU
Проект ReactOS