System Calls in windows & Native API?
If you’re doing assembly programming under Windows you don’t do manual syscalls. You use NTDLL and the Native API to do that for you. The Native API is simply a wrapper around the kernelmode side of things. All it does is perform a syscall for the correct API. You should NEVER need to manually syscall … Read more