| antiDebug
Tricks |
OS |
download |
| IsDebuggerPresent |
NT |
|
| IsDebuggerPresent -
mod1 |
NT |
|
| IsDebuggerPresent -
mod2 |
NT |
|
| IsDebuggerPresent -
mod3 |
NT |
|
| IsDebuggerPresent -
mod4 |
NT |
|
| HideDebugger - antiIDP |
NT |
|
| HideDebugger - FindWindow |
NT |
|
| HideDebugger -OpenProcess |
NT |
|
| OllyInvisible 1 |
NT |
|
| OllyInvisible 2 |
NT |
|
| NtGlobalFlag |
NT |
|
| ProcessHeap |
NT |
|
| CheckRemoteDebuggerPresent |
NT |
|
| ZwQueryInformationProcess |
NT |
|
| RDTSC |
ALL |
|
| TLS CallBack |
ALL |
|
| OllyDBG Registry detect
1 |
ALL |
|
| OllyDBG Registry detect
2 |
ALL |
|
| OllyDBG Registry detect
3 |
ALL |
|
| OllyDBG prefixes |
ALL |
|
| OllyDBG OutputDebugString |
ALL |
|
| OllyDBG Bad PeHeader |
ALL |
|
| OllyDBG - OpenProcess |
ALL |
|
| OllyDBG ESI trick |
Windows
XP SP1 |
|
| OllyDBG Bad File name |
ALL |
|
| Detect Hardware BPX |
ALL |
|
| Dll debugging 1 |
ALL |
|
| Dll debugging 2 |
ALL |
|
| AntiICE |
ALL |
|
| Debugger INT3 |
ALL |
|
| OllyDBG PageGuard |
ALL |
|
| LDR_MODULE AntiDebug |
NT |
|
| AntiOllyDBG.exe |
Millenium |
|
| SingleStep
detection |
ALL |
|
| AntiICE (via INT 1h/41h) |
ALL |
|
| AntiNTICE (EnumDeviceDrivers) |
NT |
|
| NtSetInformationThread |
NT |
|