Skip to primary content
Skip to secondary content

ntquery

Reverse Engineering, Coding

ntquery

Main menu

  • Home
  • About

Tag Archives: ThreadHideFromDebugger

Anti-Debug NtCreateThreadEx

Posted on March 29, 2014 by ntquery
Reply

NtCreateThreadEx is a new API since Vista and it is very powerful. It is mostly used for DLL injection, but it can be used as an anti-debug trick aswell. No anti-anti-debug tool/plugin can defeat this. Continue reading →

Posted in Anti-Debug, Windows Internals | Tagged anti-debug, IDA, NtCreateThreadEx, ollydbg, ThreadHideFromDebugger, ZwCreateThreadEx | Leave a reply

Recent Posts

  • Windows 10: New Anti-Debug OutputDebugStringW
  • Scylla and Api Set Map
  • Anti-Debug NtQueryObject
  • Anti-Debug Fiber Local Storage (FLS)
  • Anti-Debug NtCreateThreadEx

Recent Comments

Anti-reverser's avatarAnti-reverser on Scylla and Api Set Map
notmy realname's avatarnotmy realname on Anti-Debug NtQueryObject
IamLupo's avatarIamLupo on Anti-Debug NtQueryObject
IamLupo's avatarIamLupo on Anti-Debug NtQueryObject
Unc3nZureD's avatarUnc3nZureD on Anti-Debug Fiber Local Storage…

Archives

  • September 2015
  • March 2014

Categories

  • Anti-Debug
  • Scylla
  • Uncategorized
  • Windows Internals

Meta

  • Create account
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.com
Create a free website or blog at WordPress.com.
  • Subscribe Subscribed
    • ntquery
    • Already have a WordPress.com account? Log in now.
  • Privacy
    • ntquery
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
Design a site like this with WordPress.com
Get started