hi
it use
in my first speedy check it dont close handle in user mode with DUPLICATE_CLOSE_SOURCE
it use
KeStackAttachProcess -> ZwClose -> KeUnstackDetachProcessmethod??
in my first speedy check it dont close handle in user mode with DUPLICATE_CLOSE_SOURCE
@R00tkitSMM