Hi,
When M$ has introduced Kernel Patch Guard and said "making hooks on kernel is bad" - did they actually provided any other solution for this?
e.g filtering files can as I understand be hadnled with minifilter drivers, but what if I need to scan registries, or I want to scan any ZwVirtualAlloc or any other thigs.. has micorsoft told also "go this way" ??
thank you.
When M$ has introduced Kernel Patch Guard and said "making hooks on kernel is bad" - did they actually provided any other solution for this?
e.g filtering files can as I understand be hadnled with minifilter drivers, but what if I need to scan registries, or I want to scan any ZwVirtualAlloc or any other thigs.. has micorsoft told also "go this way" ??
thank you.