The regs.ecx register holds **argv and regs.edx **envp, with the current structure describing the current task, we get all the needed information to know what is going on at any time.
英
美
- 只要对他做些改动,他就是管理员的一个不错的系统监视工具,能把所有执行过的命令全部写到内核日志中去。