SharpHellsGate
SharpHellsGate copied to clipboard
Question
Q: Instead of getting the Syscall ID why can't we just read 24bytes from ModuleStream, After all, not all functions start with 0x4c, 0x8b, 0xd1, 0xb8