Slide 15
Slide 15 text
ANTI ANALYZE
1 1SPDFTT&OWJSPONFOU#MPDL
CJU

15
...
BeingDebugged
...
ImageBaseAddress
Ldr
...
Processheap
...
NtGlobalFlag
...
PEB
0x02
0x08
0x0c
0x18
0x68
...
InLoadOrderModuleList
InMemoryOrderModuleList
InInitializationOrderModuleList
...
_PEB_LDR_DATA
LIST_ENTRY
LIST_ENTRY
LIST_ENTRY
0x0c
0x14
0x1c