Kext implementation that intercepts file system usage

How do most antivirus programs block the io file system in case of an infected file? I suppose all the magic is in some kind of ordinary kext for this. Can someone point me to some topics? Some working example would also be great. I read apple docs about kext development, but basically all about hardware drivers, and I could not find what I needed.

+3
source share
1 answer

Well, it seems to me that I have found what I need. http://developer.apple.com/mac/library/technotes/tn2005/tn2127.html

+2
source

Source: https://habr.com/ru/post/1745062/


All Articles