You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

13 lines
245 B

2 years ago
# AntiKernelDebug-poc
2 years ago
2 years ago
## What's this?
A POC about how to detect windows kernel debug by pool tag.
## How does this poc actually work?
Query system pool tag information matches TagUlong == 'oIdK'.
Tested in Win10 1809
2 years ago
![image](images/1.png)