BOOLEAN APCReadProcessMemory(ULONG PID, PVOID targetaddress, ULONG length, PVOID retdata){
PEPROCESS pepro; KAPC_STATE kapc = { 0 }; pepro = LookupProcess((HANDLE)PID); if (pepro == NULL) return FALSE;
ObDereferenceObject(pepro); __try {
KeStackAttachProcess(pepro, &kapc);
ProbeForRead(targetaddress, length, sizeof(CHAR));
RtlCopyMemory(retdata, targetaddress, length);
KeUnstackDetachProcess(&kapc);
__except (EXCEPTION_EXECUTE_HANDLER) {
KeUnstackDetachProcess(&kapc);
return FALSE;
}
return TRUE;
}
BOOLEAN APCWriteProcessMemory(ULONG PID, PVOID targetaddress, ULONG length, PVOID Indata){
PEPROCESS pepro; KAPC_STATE kapc = { 0 }; pepro = LookupProcess((HANDLE)PID);
if (pepro == NULL) return FALSE;
ObDereferenceObject(pepro); ULONG64 Cr0;
__try {
KeStackAttachProcess(pepro, &kapc);
Pr