EventPairs Reversing – EventPairHandle as Anti-Dbg Trick

May 6, 2009


I’ve published

EventPairs Reversing – EventPairHandle as Anti-Dbg Trick

The paper is here:


Have a nice read 🙂

Giuseppe ‘Evilcry’ Bonfa’

NtSetDebugFilterState as Anti-Dbg Trick Reverse Engineering

January 9, 2009

Here you can download my last paper related to NtSetDebugFilterState UndocumentAPI that can be used as 
Anti Debugging Trick.


Have a Nice Read 🙂
Giuseppe 'Evilcry' Bonfa'

Debugger Detection Via NtSystemDebugControl

September 15, 2008


NtSystemDebugControl() is a really powerful undocumented function, that allows you Direct Manipulation of System’s Structures.

Here a definition of NtSystemDebugControl:


The use of this function is only limited to the fancy of the coder

I’ve rewritten some basical Anti Debugging Techniques with Direct Structure Reading with NtSystemDebugControl. Obviously there are shorter ways to implement these Anti-Dbg Apps, but I think that more reimplementations exists and more are possibilities to trick an attacker, that may not know/understands the specific trick..especially if embedded in many..many.. Junk Code

Here you can download the Source Code sample:


Have a nice Day,