bluehacker

Obtaining KeServiceDescriptorTableShadow address

InWindowsNTbasedoperatingsystemeverysystemcalloriginatedinusermodewhichistobeprocessedbythesystem抯kernelmustgothroughthegatetothekernelitselfwhereitwouldbedispatchedandexecuted.ThisgateisaninterruptINT2Eh.Whileontheusersidelibraryntdll.dllhandlesasy

IRP hooking and Device Chains