|
发表于 2019-1-16 00:18:55
|
显示全部楼层
你可以使用SystemExtendedHandleInformation,对应结构体SYSTEM_HANDLE_INFORMATION_EX。- typedef struct _SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX
- {
- PVOID Object;
- ULONG_PTR UniqueProcessId;
- ULONG_PTR HandleValue;
- ULONG GrantedAccess;
- USHORT CreatorBackTraceIndex;
- USHORT ObjectTypeIndex;
- ULONG HandleAttributes;
- ULONG Reserved;
- } SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX, *PSYSTEM_HANDLE_TABLE_ENTRY_INFO_EX;
- typedef struct _SYSTEM_HANDLE_INFORMATION_EX
- {
- ULONG_PTR NumberOfHandles;
- ULONG_PTR Reserved;
- SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX Handles[1];
- } SYSTEM_HANDLE_INFORMATION_EX, *PSYSTEM_HANDLE_INFORMATION_EX;
复制代码 |
|