├── .gitignore ├── LICENSE ├── README.md └── menu.png /.gitignore: -------------------------------------------------------------------------------- 1 | # Prerequisites 2 | *.d 3 | 4 | # Compiled Object files 5 | *.slo 6 | *.lo 7 | *.o 8 | *.obj 9 | 10 | # Precompiled Headers 11 | *.gch 12 | *.pch 13 | 14 | # Compiled Dynamic libraries 15 | *.so 16 | *.dylib 17 | *.dll 18 | 19 | # Fortran module files 20 | *.mod 21 | *.smod 22 | 23 | # Compiled Static libraries 24 | *.lai 25 | *.la 26 | *.a 27 | *.lib 28 | 29 | # Executables 30 | *.exe 31 | *.out 32 | *.app 33 | -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- 1 | MIT License 2 | 3 | Copyright (c) 2021 k273811702 4 | 5 | Permission is hereby granted, free of charge, to any person obtaining a copy 6 | of this software and associated documentation files (the "Software"), to deal 7 | in the Software without restriction, including without limitation the rights 8 | to use, copy, modify, merge, publish, distribute, sublicense, and/or sell 9 | copies of the Software, and to permit persons to whom the Software is 10 | furnished to do so, subject to the following conditions: 11 | 12 | The above copyright notice and this permission notice shall be included in all 13 | copies or substantial portions of the Software. 14 | 15 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR 16 | IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 17 | FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE 18 | AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER 19 | LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, 20 | OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE 21 | SOFTWARE. 22 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # ProcessesManager 2 | 一款windows64位的ark工具 rootkit 3 | 进程,线程,模块,驱动等 4 | 5 | # 使用方法 6 | * 加载符号表,请点击菜单项 main->加载符号,电脑首次运行软件需要,获取符号表过程中会卡顿 7 | * ![image](menu.png) 8 | * 如果电脑不能访问符号表,需要自行下载,然后拷贝到软件根目录/syms下面 9 | * symchk.exe /r C:\Windows\System32\ntoskrnl.exe /s SRV*c:\symbols*http://msdl.microsoft.com/download/symbols 10 | * symchk.exe /r C:\Windows\System32\hal.dll /s SRV*c:\symbols*http://msdl.microsoft.com/download/symbols 11 | * symchk.exe /r C:\Windows\System32\user32.dll /s SRV*c:\symbols*http://msdl.microsoft.com/download/symbols 12 | * symchk.exe /r C:\Windows\SysWow64\user32.dll /s SRV*c:\symbols*http://msdl.microsoft.com/download/symbols 13 | 14 | # 功能OneDbg命令支持及示例 15 | 命令参考windbg命令,**注意16进制的地址需要加0x,不加会以10进制计算** 16 | * dt [[module!]!Name] [filed] [Address] 显示结构体 em: dt _PEB 0x401000;dt ntdll!_PEB 17 | * dt6 [[module!]!Name] [Address] wow64进程下显示 64位的结构体 em: dt _PEB64 18 | * .reload [modulePath] 加载符号表 em:.reload C:\Windows\System32\ntoskrnl.exe 19 | * .cls 清屏 20 | 21 | * eb address value 以单字节写入内存 em: eb 0x401000 1 22 | * ew address value 以双字节写入内存 em: ew 0x401000 0x1111 23 | * ed address value 以四字节写入内存 em: ed 0x401000 0x4a5c1111 24 | * eq address value 以八字节写入内存 em: eq 0x401000 0x1111ffff123123 25 | 26 | * db address [Range] 以单字节读内存 em: db 0x401000 27 | * dw address [Range] 以双字节读内存 em: dw 0x401000 28 | * dd address [Range] 以四字节写入内存 em: dd 0x401000 ; dd 0x401000 20 29 | * dq address [Range] 以八字节写入内存 em: dq 0x401000 30 | * dbs address [Range] 31 | * dws address [Range] 32 | * dds address [Range] 33 | * dqs address [Range] 34 | 35 | * da address 显示ansi字符串 36 | * du address 显示unicode字符串 37 | * du8 address 显示utf8字符串 38 | 39 | * .sympath [path] 设置符号路径 em:.sympath SRV\*E:\symbol\*http://msdl.microsoft.com/download/symbols BlackINT3大神的国内符号下载http://msdl.blackint3.com:88/download/symbols 40 | 41 | * x [[module!]Name]模糊查找符号 em: x ntdll!*PEB*; x ntkrnlmp!PsGet* 42 | -------------------------------------------------------------------------------- /menu.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/k273811702/NoOne/ca13a775b2b5e018b828a03f441f067198d27e71/menu.png --------------------------------------------------------------------------------