How to find the entry point to a specific thread in Windows?

I am trying to figure out how to find the entry point of a specific thread on Windows. I know about the various ways to get the entry point into the process, but not about the thread . I looked at several different structures / methods ( TIB, PEBand GetThreadContext) that may have access to it, but it seems that is not the case. I also checked the structure of the information CREATE_THREAD_DEBUG_INFOthat has access to the initial procedure, but it seems that the only way to fill it out is to actively debug the process and call it WaitForDebugEvent. Any ideas?

Thank!

+3
source share
2 answers

NtQueryInformationThread ThreadQuerySetWin32StartAddress:

http://msdn.microsoft.com/en-us/library/ms684283%28VS.85%29.aspx

+5

:

  • CreateThread
  • exe IDA Pro ( , )
0

Source: https://habr.com/ru/post/1760678/


All Articles