What is Nostr?
Tyler Burns
npub1d30…ynp3
2024-07-19 15:27:50
in reply to nevent1q…4n3j

Tyler Burns on Nostr: No, you don't need kernel mode access to hook into API calls like ...

No, you don't need kernel mode access to hook into API calls like NtReadVirtualMemory, NtOpenProcess, etc which are all API calls that exist in usermode space. Having usermode hooks certainly makes it easier for malware to thus unhook the security agent and avoid detection. So it is a trade off.
Author Public Key
npub1d30mhvhd0sagmu83wdm26wqk00heptfn05xvgmfx7r9xscstnfcs7xynp3