52ky 发表于 2021-5-13 13:42:33

FastSystemCallHook

FastSystemCallHook代码是我编写的KiFastSystemCall钩子,它通过替换SYSENTER MSR钩住所有用户模式api。它也适用于多处理器系统,如果你想的话,应该很容易扩展到一个功能齐全的库中。

(A snippet of code which is a KiFastSystemCall hook I wrote that hooks all user-mode APIs by replacing the SYSENTER MSR. It works also on multi-processor systems and should be easy to extend into a fully functional library if you want to.)


页: [1]
查看完整版本: FastSystemCallHook