Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results

Before Posting...
Please check out the Community Guidelines in the Announcements and Administration Category.

More Info on Driver Writing and Debugging

The free OSR Learning Library has more than 50 articles on a wide variety of topics about writing and debugging device drivers and Minifilters. From introductory level to advanced. All the articles have been recently reviewed and updated, and are written using the clear and definitive style you've come to expect from OSR over the years.

Check out The OSR Learning Library at:

list if module

BiboGBiboG Member Posts: 13

If someone will use an injection method manual map and after that if I get all modules of the process in kernel space, can I see DLL file?


  • 0xrepnz0xrepnz Member Posts: 43
    edited October 2020

    You need to provide more details:

    • How is the injected code mapped to the process?
    • How do you try to get all the modules of the process in kernel space?
    • What are you trying to do exactly?

    The only place that contains "a list of modules" in a process is the loader database in user-mode which can be fetched by calling the Win32 (EnumProcessModules)

    In kernel mode, as far as I know, other than maintaining your own list with the image load callback or hacky solutions like scanning the address space with ZwQueryVirtualMemory you won't be able to get the "loaded module list".

    Unless you explain your intent, it's hard to answer your question.

    - Ori Damari
Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Upcoming OSR Seminars
OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!
Writing WDF Drivers 7 Dec 2020 LIVE ONLINE
Internals & Software Drivers 25 Jan 2021 LIVE ONLINE
Developing Minifilters 8 March 2021 LIVE ONLINE