#ifndef _NTDBG_H
NTSYSCALLAPI
NTSTATUS
NTAPI
NtRemoveProcessDebug(
_In_ HANDLE ProcessHandle,
_In_ HANDLE DebugObjectHandle
);
View code on GitHub
#ifndef _NTZWAPI_H
NTSYSCALLAPI
NTSTATUS
NTAPI
ZwRemoveProcessDebug(
_In_ HANDLE ProcessHandle,
_In_ HANDLE DebugObjectHandle
);
View code on GitHub
Function NtRemoveProcessDebug detach debugger from process. It's reverse of NtDebugActiveProcess function.
HANDLE to process being debugged.
HANDLE to Debug Object.