User-Mode hoooks - JMP Based Hook: NtAllocateVirtualMemory NtFreeVirtualMemory NtSetInformationProcess - PUSH; RET Based Hook: NtMapViewOfSection NtUnmapViewOfSection NtContinue RegNtCallbackObjectContextCleanup RegNtPostCreateKey RegNtPostCreateKeyEx RegNtPostDeleteKey RegNtPostDeleteValueKey RegNtPostEnumerateKey RegNtPostEnumerateValueKey RegNtPostFlushKey RegNtPostKeyHandleClose RegNtPostLoadKey RegNtPostOpenKey RegNtPostOpenKeyEx RegNtPostQueryKey RegNtPostQueryKeyName RegNtPostQueryKeySecurity RegNtPostQueryMultipleValueKey RegNtPostQueryValueKey RegNtPostRenameKey RegNtPostReplaceKey RegNtPostRestoreKey RegNtPostSaveKey RegNtPostSetInformationKey RegNtPostSetKeySecurity RegNtPostSetValueKey RegNtPostUnLoadKey RegNtPreCreateKey RegNtPreCreateKeyEx RegNtPreDeleteKey RegNtPreDeleteValueKey RegNtPreEnumerateKey RegNtPreEnumerateValueKey RegNtPreFlushKey RegNtPreKeyHandleClose RegNtPreLoadKey RegNtPreOpenKey RegNtPreOpenKeyEx RegNtPreQueryKey RegNtPreQueryKeyName RegNtPreQueryKeySecurity RegNtPreQueryMultipleValueKey RegNtPreQueryValueKey RegNtPreRenameKey RegNtPreReplaceKey RegNtPreRestoreKey RegNtPreSaveKey RegNtPreSetInformationKey RegNtPreSetKeySecurity RegNtPreSetValueKey RegNtPreUnLoadKey NtAddBootEntry NtAdjustPrivilegesToken NtAllocateVirtualMemory NtAllocateVirtualMemoryEx NtCreateMutant NtDelayExecution NtDeleteBootEntry NtGdiBitBlt NtLoadDriver NtMapViewOfSection NtMapViewOfSectionEx NtModifyBootEntry NtOpenCreateFile NtOpenProcessToken NtOpenProcessTokenEx NtOpenThreadToken NtOpenThreadTokenEx NtProtectVirtualMemory NtQueryInformationTokenTokenUser NtQuerySystemInformation NtQueueApcThread NtQueueApcThreadEx NtQueueApcThreadEx2 NtReadVirtualMemory NtSetContextThread NtSetInformationProcess NtSetInformationProcessCriticalProcess NtSetInformationThreadCriticalThread NtSetInformationThreadHideFromDebugger NtSetInformationThreadImpersonationToken NtSetInformationThreadWow64Context NtSetInformationVirtualMemory NtSystemDebugControl NtUnmapViewOfSection NtUnmapViewOfSectionEx NtUserGetAsyncKeyState NtUserGetClipboardData NtUserSetWindowsHookEx NtWriteVirtualMemory