I was using NtOpenDirectoryObject -> NtQueryDirectoryObject (retrieving multiple records) for "\Driver" & "\Device" but it (1) doesn't return all entries I can see in Winobj and (2) the entries it returns are inconsistent across versions? Anyone have any insights?

Maybe it is because winobj is running with higher privelegies compared to your development enviroment?
-
-
I'm running as Admin & I am looping NtQueryDirectoryObject to increase the buffer size till I no longer get STATUS_BUFFER_TOO_SMALL or STATUS_MORE_ENTRIES
-
is there a possibility of obj names containing console control characters that gets parsed, though messing up output?
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.