HEX DEREF SUPPORT

#983
Title: How to / Terminology in the software
Administrator
04/01/2022 23:39 - 57 days 13 hours 2 minutes
#983
Kernel mode (KM)
Kernel driver interface (KDI)

How to use the handle elevation DKOM feature?

1) KDI->Initialize
2) KDI->Load the driver
3) Open the process in the tool whose handle you want to elevate
4) Hover over the process or select a process in HEX DEREF and then right-click to elevate the handle

If you use HEX DEREF to scan process memory that is protected by a kernel level anti-cheat. Make sure you you disable KM:

Edit->Settings->Memory viewer->Use the kernel driver to read or write an arbitrary kernel or user process memory

Every time when you reboot your computer. Before you can browse the kernel memory. You must repeat steps 1 and 2.

Post a comment

Registered users do not have to enter captcha. A line in the code tag is currently limited to maxium of 160 characters.
Posting guidelines: You may not post any personal information. When you report an issue: Always mention which version and operating system and briefly describe the issue. Any support request post that does not include this information will be removed as spam without a reply.
Title
Tags You may use the following tags: [QUOTE] [/QUOTE] [B] [/B] [URL] [/URL] [CODE] [/CODE]
Captcha Please enter the text you see (case insensitive). The listed characters must be entered clockwise starting from twelve o'clock.
Comments are moderated Y