A snippet of code which is a KiFastSystemCall hook I wrote that hooks all user-mode APIs by replacing the SYSENTER MSR. It works also on multi-processor systems and should be easy to extend into a fully functional library if you want to.
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)