Feb. 2, 2023, 7 p.m. | Dr Josh Stroschein

Dr Josh Stroschein www.youtube.com

There are a several key internal structures in the Windows operating system that are regularly used to obtain non-standard functionality. The process environment block, commonly referred to as the PEB, is one of those structures. In this video, we'll discuss the overall structure of the peb and use WinDbg to view it's structure. We'll also look at a sample program that walks the peb to find the base of NTDLL and discuss how this code works and how you can …

base block discover discuss environment find how-to internal key memory non operating system process program standard system video windbg windows

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC