ARK之进程枚举

本文详细介绍了在Windows系统中进行进程枚举的多种方法,包括CreateToolhelp32Snapshot、EnumProcesses、ZwQuerySystemInformation等API,以及通过内核级别技巧如活动链、句柄表和Csrss.exe等进行进程枚举。每种方法都有其适用场景和特点,对于系统监控和调试非常有用。
摘要由CSDN通过智能技术生成
A.进程
1.
CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS) /  Process32First / Process32Next
void main()
{
HANDLE hSnap = CreateToolhelp32Snapshot( TH32CS_SNAPPROCESS, 0 );
if( hSnap == INVALID_HANDLE_VALUE )
{
   cout<<"Create Toolhelp false"<<endl;
   return;
}
PROCESSENTRY32 pEntry32 = {0};
pEntry32.dwSize = sizeof(PROCESSENTRY32);
bool bRes = Process32First( hSnap, &pEntry32 );
int pNums = 0;
while( bRes )
{
   pNums++;
   cout<<"PID:"<<pEntry32.th32ProcessID<<"\t"<<"Path:"<<pEntry32.szExeFile<<endl;
   bRes = Process32Next( hSnap, &pEntry32 );
}
CloseHandle( hSnap );
cout<<"Process Nums:"<<pNums<<endl;


}




2.PsApi EnumProcess
DWORD dProcessIds[1024] = {0};
DWORD dRet = 0;
DWORD dRes = 0;


dRes = EnumProcesses( dProcessIds, sizeof(dProcessIds), &dRet );
if( dRes == 0 )
{
   cout<<"EnumProcesses1 False"<<endl;
   return;
}
int ProcessNums = dRet/sizeof(DWORD);


for( int i = 0; i < ProcessNums; i++ )
   GetProcessPathById( dProcessIds[i] );


cout<<"Process Nums:"<<ProcessNums<<endl;



3.ZwQuerySystemInformation(SystemProcessesAndThreadsInformation)5号 和16号功能SystemProcessesAndThreadsInformation
代码是R0的 但R3也可以使用
5号功能:
NTSTATUS Status = STATUS_SUCCESS;
NtQuerySystemInformation( 5, pBuff, 0, &uRet );


pBuff = (PCHAR)ExAllocatePool( NonPagedPool, uRet );
pTemp = pBuff;


Status = NtQuerySystemInformation( 5, pBuff, uRet, NULL );
if( NT_SUCCESS(Status) )
{
  
   while( 1 )
   {
    PSYSTEM_PROCESS_INFORMATION pSystemProcessInfo = (PSYSTEM_PROCESS_INFORMATION)pTemp;
    RtlUnicodeStringToAnsiString( &ansi, &pSystemProcessInfo->ImageName, TRUE );
    DbgPrint("PId:%d\t", pSystemProcessInfo->ProcessId);
    DbgPrint("Path:%s\n", ansi.Buffer );
    RtlFreeAnsiString( &ansi );


    if( pSystemProcessInfo->NextEntryOffset == 0 )
     break;
    pTemp = pTemp+pSystemProcessInfo->NextEntryOffset;


   }


}


16号功能:
void EnumProcessBy_16()
{
NTSTATUS Status = STATUS_SUCCESS;
PCHAR pBuff = NULL;
ULONG uNums = 0;
ULONG uRet = 0;
PSYSTEM_HANDLE_INFORMATION_EX pSystemHandle = NULL;


pBuff = (PCHAR)ExAllocatePool( NonPagedPool, 100 );


Status = ZwQuerySystemInformation( 16, pBuff, 100, &uRet );
ExFreePool( pBuff );


pBuff = (PCHAR)ExAllocatePool( NonPagedPool, uRet );


Status = ZwQuerySystemInformation( 16, pBuff, uRet, NULL );
if( NT_SUCCESS(Status) )
{
   ULONG index = 0;
   LONG PId = -1;
   pSystemHandle = (PSYSTEM_HANDLE_INFORMATION_EX)pBuff;
   uNums = pSystemHandle->NumberOfHandles;


   for(; index < uNums; index++ )
   {
    if( pSystemHan
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值