summaryrefslogtreecommitdiff
path: root/general/obcallback
diff options
context:
space:
mode:
authorBarry Golden <[email protected]>2019-09-16 19:18:24 -0700
committerGitHub <[email protected]>2019-09-16 19:18:24 -0700
commit42f70c9a35f678ec45995ef90e2d59cb459597d3 (patch)
treecf387cfdff1d69f81bc8f5a30c4fd778e21f2385 /general/obcallback
parentf064dfb2d92ac3f1f4344d435e4690e4339b5025 (diff)
Update README.md (#418)847358473484733847328473184730
Diffstat (limited to 'general/obcallback')
-rw-r--r--general/obcallback/README.md17
1 files changed, 3 insertions, 14 deletions
diff --git a/general/obcallback/README.md b/general/obcallback/README.md
index 782c7127..993b78d6 100644
--- a/general/obcallback/README.md
+++ b/general/obcallback/README.md
@@ -8,28 +8,17 @@ products:
- windows-wdk
---
-
-
-<!---
- name: ObCallback Callback Registration Driver
- platform: WDM
- language: cpp
- category: General
- description: Demonstrates the use of registered callbacks for process protection.
- samplefwlink: http://go.microsoft.com/fwlink/p/?LinkId=617716
---->
-
# ObCallback Callback Registration Driver
The ObCallback sample driver demonstrates the use of registered callbacks for process protection. The driver registers control callbacks which are called at process creation.
## Design and Operation
-The sample exercises both the [**PsSetCreateProcessNotifyRoutineEx**](http://msdn.microsoft.com/en-us/library/windows/hardware/ff559951) and the [**ObRegisterCallbacks**](http://msdn.microsoft.com/en-us/library/windows/hardware/ff558692) routines. The first example uses the **ObRegisterCallbacks** routine and a callback to restrict requested access rights during a open process action. The second example uses the **PsSetCreateProcessNotifyRoutineEx** routine to reject a process creation by examining the command line.
+The sample exercises both the [**PsSetCreateProcessNotifyRoutineEx**](https://docs.microsoft.com/windows-hardware/drivers/ddi/content/ntddk/nf-ntddk-pssetcreateprocessnotifyroutine) and the [**ObRegisterCallbacks**](https://docs.microsoft.com/windows-hardware/drivers/ddi/content/wdm/nf-wdm-obregistercallbacks) routines. The first example uses the **ObRegisterCallbacks** routine and a callback to restrict requested access rights during a open process action. The second example uses the **PsSetCreateProcessNotifyRoutineEx** routine to reject a process creation by examining the command line.
The following is a command line usage scenario to exercise access restriction:
-```
+```cmd
C:\> obcallbacktestctrl.exe -? (for command line help)
C:\> obcallbacktestctrl.exe -install (installs the kernel driver)
C:\> obcallbacktestctrl.exe -name notepad (specifies that the string "notepad" will be watched as a protected executable)
@@ -49,7 +38,7 @@ C:\> obcallbacktestctrl.exe -uninstall (uninstall the kernel drive
The following is another sample test you can run to prevent a process from being created:
-```
+```cmd
C:\> obcallbacktestctrl.exe -install (installs the kernel driver)
C:\> obcallbacktestctrl.exe -reject notepad (specifies that the string "notepad" will be watched and prevented from starting as a process)