The PEB is not a kernel mode data structure itself. It resides in the application mode address space of the process that it relates to

https://en.wikipedia.org/wiki/Process_Environment_Block

https://www.ired.team/miscellaneous-reversing-forensics/windows-kernel-internals/exploring-process-environment-block

https://www.ired.team/offensive-security/defense-evasion/masquerading-processes-in-userland-through-_peb

DEBUG AND ANTI-DEBUG TIPS AND TRICKS EXPLORING PEB STRUCTURE:

https://rvsec0n.wordpress.com/2019/09/13/routines-utilizing-tebs-and-pebs/

on x64dbg you can press ctrl + g to open the “Enter expression to follow…” and type:

peb()
 
or 
 
ted()

🌱 Back to Garden