According to https://github.com/tklengyel/drakvuf/issues/122#issuecomment-472950094, The current KPRCB->CurrentThread->Process method could be with Windows Vista too. Is there something else to prevent DRAKVUF to support Windows Vista ?