How does SysInternal's ProcessMonitor work? - Stack Overflow
Jan 27, 2011 · This handler takes a system call number, which is passed in a machine register, and indexes into a system service table to find the address of the NT function that will handle the request. By replacing entries in this table with pointers to hooking functions, it is possible to intercept and replace, augment, or monitor NT system services.
DA: 68 PA: 96 MOZ Rank: 11