Last updated 6 months ago
NtQuerySystemInformation use the vaguely documented structure: SYSTEM_PROCESS_INFORMATION, many of the parameters are reserved to hide the functionality.
SYSTEM_PROCESS_INFORMATION
Here is a reference to use for SYSTEM_PROCESS_INFORMATION: