Research-focused userland proof-of-concept demonstrating API hooking of NtQuerySystemInformation to analyze and manipulate SYSTEM_PROCESS_INFORMATION structures. The project explores DKOM-style process hiding techniques to better understand Windows internals, detection gaps, and blue-team countermeasures in controlled lab environments only.
-
Updated
Feb 22, 2026