A POC about how to detect windows kernel debug by pool tag.
Query system pool tag information matches TagUlong == 'oIdK'.
Tested in Win10 1809
- Visual Studio 2022
- llvm-msvc [link]
A POC about how to detect windows kernel debug by pool tag.
Query system pool tag information matches TagUlong == 'oIdK'.
Tested in Win10 1809