network, filtering, 139–140
network filters, diagrammed, 140
newFileSysDevice, device pointer, 146–150
newKeyboardDevice global variable, key logging, 172–173
newNetworkDevice, device pointer, 146–150
NewSystemCallTable
Ghost.c file variable, 33–36
hookManager.h file variable, 37–38
system call table diagrammed, 30
NewZwEnumerateKey, function, 202
NewZwMapViewOfSection function
function, 54–63
hookManager.c file, 36–37
hookManager.h file, 37–38
process injection, 47
NewZwOpenKey, function, 202
NewZwQueryKey, function, 202
noTransferOp, function, 78–96
ntddk.h
defining a hook function, 47
Memory Descriptor List, 28–29
ntdll.dll, functions in, 39
ntoskrnl.exe, kernel hooking problems and, 42