Manual syscalls
Direct syscalls


Indirect syscalls
References
Last updated


Last updated
.code
NtOpenProcess proc
mov r10, rcx
mov eax, 26h
syscall
ret
NtOpenProcess endp
NtClose proc
mov r10, rcx
mov eax, 0Fh
syscall
ret
NtClose endp
endEXTERN ntCloseSyscall:QWORD
.code
IndirectSyscalls proc
mov r10, rcx
mov eax, 26h ; <- ssn of NtOpenProcess
jmp QWORD PTR [ntCloseSyscall] ; <- jmp to syscall in NtClose
IndirectSyscalls endp
end