I want to intercept file (ReadFile, WriteFile) operations and registry calls of some program. I decided that filter driver will be the best solution. Is it possible to do that from WDF or I need to learn WDM? Are there any samples?

有帮助吗?

解决方案

OK, minifilter is the right solution

许可以下: CC-BY-SA归因
不隶属于 StackOverflow
scroll top