Learning Goals: Practice WinDbg for Intercepting Driver Loading Practice IMM for Modifying Binary Code Trace and Modify Control Flow Using IMM Applicable to: Operating Systems Assembly Language Operating System Security 1. Introduction One typical feature of Max++ is its ability to hide malicious files in a hidden drive. In this tutorial, we show you how to modify the malware itself to break its h