GIAC
GREM · Question #163
A malware modifies the Import Address Table of a process at runtime. Which technique is being used?
The correct answer is A. IAT hooking. See the full explanation below for the reasoning.
Question
A malware modifies the Import Address Table of a process at runtime. Which technique is being used?
Options
- AIAT hooking
- BDLL injection
- CExport redirection
- DHeap pivoting
How the community answered
(37 responses)- A81% (30)
- B5% (2)
- C11% (4)
- D3% (1)
Community Discussion
No community discussion yet for this question.