Hijack the method table in runtime

!address to get all the exports

x ntdll!RtlFindExportedRoutineByName

if sos isn’t there, .load C:\\Program Files\\WindowsApps\\Microsoft.WinDbg_1.2210.3001.0_x64__8wekyb3d8bbwe\\amd64\\winext\\sos\\sos.dll or `

xpn (.net, not framework)

.net framework

CLR

CLR shit

Sacrificial Appdomains

Managed hooking

Other

NtCreateUserProcess

COFF Loading