Develop based on HyperPlatForm and Only x64.
Support log process' systemcalls and easy ept-hook (NtOpenProcess or NtCreateFile .etc)
Support hook win32kfull.sys funtions.
Add hide window (attack gpKernelHandleTable and hook FindWindow).
header file "settings.h" ,hooked functions are implemented at service_hook.cpp about line 360
PDBSDK.h
1.failed to unhook NtDeviceIoControlFile(reference is not zero)