@@ -0,0 +1,8 @@
# Etw-Syscall
捕获syscall调用就如同用windows defender的接口一样
具体流程
https://key08.com/index.php/2021/10/19/1375.html
代码不好看 因为是临时试验
The note is not visible to the blocked user.