- IsDebuggerPresent
- CheckRemoteDebuggerPresent
- CloseHandle(0xDEADC0DE)
- ZwQueryInformationProcess(ProcessDebugObjectHandle), called correctly
- crc32 check on direct syscall
- ZwQueryInformationProcess(ProcessDebugObjectHandle), called with ReturnLength == ProcessInformationClass
nicelnicel/XAntiDebug
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|