Skip to content

senko37/createprocessnotify-hook

Repository files navigation

createprocessnotify-hook

PsSetCreateProcessNotifyRoutine/Ex/Ex2 hook. Tested on Windows 11 (22H2)

To do:

  • Add function to remove hook from callback
  • Use PsLoadedModuleList instead of DriverObject->DriverSection