The more serious players shadow Windows events.
The real stuff does process injection and directly shadow copies / modifies in-memory data structures.
The more serious players shadow Windows events.
The real stuff does process injection and directly shadow copies / modifies in-memory data structures.