Sam Russell
LODSB

LODSB

NtSetInformationThread: Disabling ThreadHideFromDebugger

Nov 25, 20214 min read

One common anti-debugging technique is to make use of the Windows API to simply mark your threads as invisible to the debugger. This isn't officially documented by Microsoft but it has been quite robust across windows versions. The documentation for ...

NtSetInformationThread: Disabling ThreadHideFromDebugger