Hello, i'd like to ask you guyz about something, if it's not allowed to ssdt hook in win x64, how do av's manage to detect and forbid certain types of access?
Is there any way to forbid OpenProcess() without ssdt hooking?
Is there any way to forbid OpenProcess() without ssdt hooking?