Usually I don't post things like this, but because KiFastSystemCall hooking only works on x86 systems and doesn't work on Windows 8 or above, it no longer has much use in malware. There are also multiple public implementations for this method, just not very elegant, which I hope to correct.
more here.........http://www.malwaretech.com/2015/04/intercepting-all-system-calls-by.html
more here.........http://www.malwaretech.com/2015/04/intercepting-all-system-calls-by.html