This macro is documented in Windows Driver Kit. It is a native equivalent of the GetCurrentProcess
function and returns a pseudo-handle that grants PROCESS_ALL_ACCESS
to the current process. You do not need to call NtClose
on the returned handle.
This pseudo-handle can be used with all functions that accept process handles.
NtCurrentThread
RtlIsCurrentProcess