一种inlineHook检测方案 - luoyesiqiu
inlinehook是修改内存中的机器码来实现hook的方式
There is a combination of lesser known tools and techniques to capture and later decrypt SSL/TLS network traffic on Windows. This technique is neat because it does not require the installation of additional driver/software when capturing the traffic.
Technique, Tools and StepsIt is quite straight forward and consists of:
If you can or want to capture traffic with Wireshark also, there is no need to use netsh of course.