--- title: Windows Kernel kind: overview topics: [windows-kernel] sources: - wiki/sources/skills/windows-kernel.md - wiki/sources/README-categories.md - wiki/sources/descriptions/HyperDbg__HyperDbg.md - wiki/sources/descriptions/hawkeye-Leo__hawkeye.md - wiki/sources/descriptions/HoShiMin__Kernel-Bridge.md - wiki/sources/descriptions/zzhouhe__PG1903.md - wiki/sources/descriptions/zxd1994__vt-debuuger.md - wiki/sources/descriptions/zorftw__revert-mapper.md - wiki/sources/descriptions/zorftw__lsass-extend-mapper.md - wiki/sources/descriptions/zodiacon__EtwExplorer.md - wiki/sources/descriptions/zodiacon__ObjectExplorer.md - wiki/sources/descriptions/zoand__BOOM.md - wiki/sources/descriptions/zer0condition__Demystifying-PatchGuard.md - wiki/sources/descriptions/zer0condition__NTMemory.md - wiki/sources/descriptions/zer0condition__hv.md - wiki/sources/descriptions/zer0condition__Ophion.md - wiki/sources/descriptions/zer0condition__ZeroThreadKernel.md - wiki/sources/descriptions/mq1n__HiddenModuleDetector.md - wiki/sources/descriptions/mq1n__DLLThreadInjectionDetector.md - wiki/sources/descriptions/pandaadir05__ghost.md - wiki/sources/descriptions/weak1337__SystemThreadFinder.md - wiki/sources/descriptions/gmh5225__StealthAPCDispatcher.md - wiki/sources/descriptions/gmh5225__Kernel-Special-APC-ReadProcessMemory.md - wiki/sources/descriptions/gmh5225__Kernel-Cactus.md - wiki/sources/descriptions/gmh5225__KasperskyHook.md - wiki/sources/descriptions/gmh5225__Eac-Injector-Driver.md - wiki/sources/descriptions/gmh5225__EASY-HWID-SPOOFER.md - wiki/sources/descriptions/gmh5225__Driver-HWID-btbd-modified.md - wiki/sources/descriptions/backengineering__msrexec.md - wiki/sources/descriptions/backengineering__VDM.md - wiki/sources/descriptions/backengineering__Voyager.md - wiki/sources/descriptions/backengineering__POC-ExFlushTb.md - wiki/sources/descriptions/basil00__Divert.md - wiki/sources/descriptions/WPO-Foundation__win-shaper.md - wiki/sources/descriptions/blaquee__dllnotif.md - wiki/sources/descriptions/bluecapesecurity__PWF.md - wiki/sources/descriptions/btbd__access.md - wiki/sources/descriptions/bootmgfw__apex-external-cheat.md - wiki/sources/descriptions/bootmgfw__lithium-kernel.md - wiki/sources/descriptions/bootmgfw__Rust-External-Cheat.md - wiki/sources/descriptions/bootmgfw__Fortnite-External-Cheat-Base.md - wiki/sources/descriptions/bromoket__access_updated.md - wiki/sources/descriptions/brew02__MountSystemPartition.md - wiki/sources/descriptions/brew02__KiUserExceptionDispatcherHook.md - wiki/sources/descriptions/brew02__FastPFHook.md - wiki/sources/descriptions/brew02__BudgetEPT.md - wiki/sources/descriptions/brew02__CovertThread.md - wiki/sources/descriptions/FaEryICE__MemScanner.md - wiki/sources/descriptions/FarmEquipment69__umap-mapper.md - wiki/sources/descriptions/btbd__umap.md - wiki/sources/descriptions/btbd__smap.md - wiki/sources/descriptions/btbd__modmap.md - wiki/sources/descriptions/btbd__wpp.md - wiki/sources/descriptions/btbd__hwid.md - wiki/sources/descriptions/BaconToaster__UC-Apex-Remastered.md - wiki/sources/descriptions/Bad-Jubies__Exploits.md - wiki/sources/descriptions/BadPlayer555__KernelGDIDraw.md - wiki/sources/descriptions/BadPlayer555__TraceCleaner.md - wiki/sources/descriptions/Barracudach__Swap-control-ioctl.md - wiki/sources/descriptions/BeneficialCode__WinArk.md - wiki/sources/descriptions/BeneficialCode__KReClassEx.md - wiki/sources/descriptions/Archie-osu__PowerHook.md - wiki/sources/descriptions/Astronaut00__DoubleDataPointer.md - wiki/sources/descriptions/AsuNa-jp__HotkeybasedKeyloggerDetector.md - wiki/sources/descriptions/AvivShabtay__Stresser.md - wiki/sources/descriptions/AyinSama__Anti-AntiDebuggerDriver.md - wiki/sources/descriptions/BlackSnufkin__AxHunter.md - wiki/sources/descriptions/BuddyBoi__KernelMoveMouse.md - wiki/sources/descriptions/gmh5225__EfiDump.md - wiki/sources/descriptions/gmh5225__ETWHOOK-InfinityHookClass.md - wiki/sources/descriptions/emlinhax__tableflipper.md - wiki/sources/descriptions/emlinhax__DbgViewEx.md - wiki/sources/descriptions/endgameinc__ClrGuard.md - wiki/sources/descriptions/ergrelet__windiff.md - wiki/sources/descriptions/everdox__InfinityHook.md - wiki/sources/descriptions/FiYHer__InfinityHookPro.md - wiki/sources/descriptions/Th3Spl__SimpleUEFI.md - wiki/sources/descriptions/Th3Spl__PerfectSMBios.md - wiki/sources/descriptions/Th3Spl__IoCreateDriver.md - wiki/sources/descriptions/1401199262__NMIStackWalk.md - wiki/sources/descriptions/1401199262__RemoteCall.md - wiki/sources/descriptions/1401199262__HookSwapContext.md - wiki/sources/descriptions/1401199262__HookHvcallCodeVa.md - wiki/sources/descriptions/1hAck-0__zeroimport.md - wiki/sources/descriptions/Th3Spl__NoImportz.md - wiki/sources/descriptions/Teach2Breach__moonwalk.md - wiki/sources/descriptions/ThomasonZhao__InfinityHookProMax.md - wiki/sources/descriptions/Oliver-1-1__SmmInfect.md - wiki/sources/descriptions/Oliver-1-1__UEFI-Graphic.md - wiki/sources/descriptions/Oliver-1-1__RwxScanner.md - wiki/sources/descriptions/Luchinkin__device-control-hooks-scanner.md - wiki/sources/descriptions/NurdAlert__modded-voyager.md - wiki/sources/descriptions/NullArray__WinKernel-Resources.md - wiki/sources/descriptions/NullTerminatorr__NullHook.md - wiki/sources/descriptions/Nitr0-G__PeVisor.md - wiki/sources/descriptions/Nou4r__pKernelInterface-EFT.md - wiki/sources/descriptions/NMan1__apex-legends-cheat.md - wiki/sources/descriptions/NMan1__external-warzone-cheat.md - wiki/sources/descriptions/NMan1__Rainbow-Six-Cheat.md - wiki/sources/descriptions/NMan1__OverflowRust.md - wiki/sources/descriptions/NMan1__OverflowR6V2.md - wiki/sources/descriptions/NMan1__Internal-Rainbow-Six-Cheat-V3.md - wiki/sources/descriptions/NSG650__NoMoreBugCheckReloaded.md - wiki/sources/descriptions/NSG650__NoMoreBugCheck.md - wiki/sources/descriptions/NSG650__BugCheckHack.md - wiki/sources/descriptions/NSG650__BugCheck2Linux.md - wiki/sources/descriptions/NSG650__Bad-Bugcheck.md - wiki/sources/descriptions/NSG650__Bad-BugCheck-Old.md - wiki/sources/descriptions/AnalogFeelings__KmdfMandelcheck.md - wiki/sources/descriptions/NSG650__NtDOOM.md - wiki/sources/descriptions/Oxygen1a1__InfinityHook_latest.md - wiki/sources/descriptions/DearXiaoGui__InfinityHookPro-main.md - wiki/sources/descriptions/Theordernarkoz__Hwid--Spoofer.md - wiki/sources/descriptions/gmh5225__EvilKaspersky.md - wiki/sources/descriptions/gmh5225__AcDrv.md - wiki/sources/descriptions/gmh5225__AetherVisor.md - wiki/sources/descriptions/gmh5225__ANGRYORCHARD.md - wiki/sources/descriptions/gmh5225__AvastHV.md - wiki/sources/descriptions/gmh5225__Hook-KdTrap.md - wiki/sources/descriptions/gmh5225__Driver-KDtour.md - wiki/sources/descriptions/SilentisVox__DoomSyscalls.md - wiki/sources/descriptions/SinaKarvandi__Hypervisor-From-Scratch.md - wiki/sources/descriptions/Sentient111__Csgo-Full-kernel.md - wiki/sources/descriptions/Sentient111__VulnerableDriverScanner.md - wiki/sources/descriptions/Sentient111__KernelDrawing.md - wiki/sources/descriptions/Sentient111__ClearDriverTraces.md - wiki/sources/descriptions/SecondNewtonLaw__DriverBase.md - wiki/sources/descriptions/Snoopy-Sec__Localroot-ALL-CVE.md - wiki/sources/descriptions/Spuckwaffel__Simple-MmcopyMemory-Hook.md - wiki/sources/descriptions/Spuckwaffel__Kernel-Thread-Driver.md - wiki/sources/descriptions/Splitx12__eft.md - wiki/sources/descriptions/SDXT__MMInject.md - wiki/sources/descriptions/SLAUC91__AntiCheat.md - wiki/sources/descriptions/gmh5225__Hook-HvlSwitchVirtualAddressSpace.md - wiki/sources/descriptions/gmh5225__Kernel-Cheat-for-directx3D.md - wiki/sources/descriptions/gmh5225__StealthSytemThreadFinderBE.md - wiki/sources/descriptions/gmh5225__Hidden-Thread-Finder.md - wiki/sources/descriptions/gmh5225__Rootkit-2.md - wiki/sources/descriptions/gmh5225__RToolZ.md - wiki/sources/descriptions/gmh5225__Fenrir.md - wiki/sources/descriptions/zer0condition__checkhv_um.md - wiki/sources/descriptions/zer0condition__gexec.md - wiki/sources/descriptions/zer0condition__GoodmansKernel.md - wiki/sources/descriptions/void-stack__Hypervisor-Detection.md - wiki/sources/descriptions/valium007__BareSVM.md - wiki/sources/descriptions/yyl-20020115__OpenArk.md - wiki/sources/descriptions/KSwordDEV__KSword.md - wiki/sources/descriptions/yardenshafir__cet-research.md - wiki/sources/descriptions/yardenshafir__WinDbg_Scripts.md - wiki/sources/descriptions/yardenshafir__SymlinkCallback.md - wiki/sources/descriptions/xuanxuan0__TiEtwAgent.md - wiki/sources/descriptions/preludeorg__ThreatIntelligenceConsumer.md - wiki/sources/descriptions/xtremegamer1__xigmapper.md - wiki/sources/descriptions/ekknod__sumap.md - wiki/sources/descriptions/ekknod__efi-monitor.md - wiki/sources/descriptions/ekknod__KiSystemStartupMeme.md - wiki/sources/descriptions/ekknod__MouseClassServiceCallbackTrick.md - wiki/sources/descriptions/ekknod__MouseClassServiceCallbackMeme.md - wiki/sources/descriptions/ekknod__SubGetVariable.md - wiki/sources/descriptions/ekknod__SetWindowHookEx.md - wiki/sources/descriptions/ekknod__Nmi.md - wiki/sources/descriptions/ekknod__smm.md - wiki/sources/descriptions/ekknod__EC.md - wiki/sources/descriptions/ekknod__Anti-Cheat-TestBench.md - wiki/sources/descriptions/xct__windows-kernel-exploits.md - wiki/sources/descriptions/hacksysteam__HackSysExtremeVulnerableDriver.md - wiki/sources/descriptions/hackerhouse-opensource__SignToolEx.md - wiki/sources/descriptions/xhscfq__UnrealVTDbg.md - wiki/sources/descriptions/xM0kht4r__VEN0m-Ransomware.md - wiki/sources/descriptions/xM0kht4r__AV-EDR-Killer.md - wiki/sources/descriptions/xaitax__NTSleuth.md - wiki/sources/descriptions/sonyps5201314__pdb.md - wiki/sources/descriptions/xPasters__.data-ptr-swap.md - wiki/sources/descriptions/oakboat__DataPtrHookWin11.md - wiki/sources/descriptions/0mWindyBug__DataptrHooks.md - wiki/sources/descriptions/muturikaranja__AfdIrpCallDispatch.md - wiki/sources/descriptions/x90skysn3k__x260-lenovo-opencore.md - wiki/sources/descriptions/x86matthew__WinVisor.md - wiki/sources/descriptions/waryas__KACE.md - wiki/sources/descriptions/Qfrost911__KACE.md - wiki/sources/descriptions/redecorate__Holodori-Kernel-Bypass.md - wiki/sources/descriptions/x86matthew__InstrumentationCallbackSyscallLogger.md - wiki/sources/descriptions/secrary__Hooking-via-InstrumentationCallback.md - wiki/sources/descriptions/paranoidninja__EtwTi-Syscall-Hook.md - wiki/sources/descriptions/ssnob__hidden_syscall_monitoring.md - wiki/sources/descriptions/wpdk__wdutf.md - wiki/sources/descriptions/winsiderss__systeminformer.md - wiki/sources/descriptions/whokilleddb__function-collections.md - wiki/sources/descriptions/wesmar__kvc.md - wiki/sources/descriptions/wesmar__KvcForensic.md - wiki/sources/descriptions/hypervisor__kli.md - wiki/sources/descriptions/gmh5225__dse_hook.md - wiki/sources/descriptions/gmh5225__Disabling-Hyper-V.md - wiki/sources/descriptions/gmh5225__Dse-Patcher-2.md - wiki/sources/descriptions/gmh5225__DisableDSE.md - wiki/sources/descriptions/gmh5225__DSEDodge-Signed-Kernel-Driver.md - wiki/sources/descriptions/gmh5225__Disable-Windows-Defender-.md - wiki/sources/descriptions/gmh5225__echoac-poc.md - wiki/sources/descriptions/gmh5225__Driver-Communication-List.md - wiki/sources/descriptions/gmh5225__Driver-Detect-nullshit.md - wiki/sources/descriptions/gmh5225__Driver-DriverNoImage.md - wiki/sources/descriptions/gmh5225__Driver-efi-bootkit.md - wiki/sources/descriptions/gmh5225__-Rainbow---EFI.md - wiki/sources/descriptions/gmh5225__Driver-HideKernelThread-IoCancelIrp.md - wiki/sources/descriptions/gmh5225__Driver-intel-PEBs-LoopHPCs.md - wiki/sources/descriptions/gmh5225__Driver-read_write.md - wiki/sources/descriptions/gmh5225__Driver-RPM-DirectPageManipulation.md - wiki/sources/descriptions/gmh5225__Driver-SessionMapper.md - wiki/sources/descriptions/gmh5225__Driver-SoulExtraction.md - wiki/sources/descriptions/gmh5225__Driver-WatchOwl.md - wiki/sources/descriptions/gmh5225__Driver-Systemthread-from-PspCidTable-src.md - wiki/sources/descriptions/gmh5225__DriverBuddyReloaded.md - wiki/sources/descriptions/gmh5225__dolboeb-executor.md - wiki/sources/descriptions/gmh5225__blood-hunt.md - wiki/sources/descriptions/gmh5225__asus-bsitf-0-day-poc.md - wiki/sources/descriptions/gmh5225__AsusDrv.md - wiki/sources/descriptions/gmh5225__bootlicker.md - wiki/sources/descriptions/gmh5225__Apex-ApexCheeseTest.md - wiki/sources/descriptions/gmh5225__Apex-CHEAT-FIXED.md - wiki/sources/descriptions/gmh5225__Apple-Lite-Fortnite-Cheat.md - wiki/sources/descriptions/gmh5225__Allocating-individual-pages.md - wiki/sources/descriptions/gmh5225__Fortnite-EFI-External.md - wiki/sources/descriptions/gmh5225__Flying-Guys-fully-modified.md - wiki/sources/descriptions/gmh5225__FallGuys.md - wiki/sources/descriptions/gmh5225__FlyingGuys.md - wiki/sources/descriptions/gmh5225__dbk64-vulnerability-driver.md - wiki/sources/descriptions/gmh5225__eac-bypass-1.md - wiki/sources/descriptions/gmh5225__EAC-Driver-UD-for-now.md - wiki/sources/descriptions/gmh5225__cheat-attack-thread-slemu.md - wiki/sources/descriptions/gmh5225__Common-Registry-Jmp-RCX.md - wiki/sources/descriptions/gmh5225__CapcomDKOM.md - wiki/sources/descriptions/gmh5225__CapcomLib.md - wiki/sources/descriptions/gmh5225__CallMeWin32kDriver.md - wiki/sources/descriptions/gmh5225__CYBERSEC2023-BYOVD-Demo.md - wiki/sources/descriptions/gmh5225__Comm-data-ptr-driver.md - wiki/sources/descriptions/gmh5225__Comm-Data-Pointer-Swap.md - wiki/sources/descriptions/gmh5225__custom_data_ptr_swap_sample.md - wiki/sources/descriptions/gmh5225__DataPtrSwap-driver.md - wiki/sources/descriptions/dayzerosec__AMD-SP-Loader.md - wiki/sources/descriptions/david942j__kvm-kernel-example.md - wiki/sources/descriptions/IcEy-999__Ntoskrnl_Viewer.md - wiki/sources/descriptions/IcEy-999__Drv_Hide_And_Camouflage.md - wiki/sources/descriptions/Ido-Moshe-Github__CiDllDemo.md - wiki/sources/descriptions/Idov31__NovaHypervisor.md - wiki/sources/descriptions/ION28__BLUESPAWN.md - wiki/sources/descriptions/IntroVirt__IntroVirt.md - wiki/sources/descriptions/daswareinfach__Battleye-VAC-EAC-Kernel-Bypass.md - wiki/sources/descriptions/charliewolfe__Stealthy-Kernelmode-Injector.md - wiki/sources/descriptions/comaeio__SwishDbgExt.md - wiki/sources/descriptions/cpz__trinity.md - wiki/sources/descriptions/crvvdev__vac-bypass-kernel.md - wiki/sources/descriptions/crvvdev__intraceptor.md - wiki/sources/descriptions/cristeigabriela__bb-viewer.md - wiki/sources/descriptions/cristeigabriela__bb.md - wiki/sources/descriptions/gmh5225__efiXplorer.md - wiki/sources/descriptions/gmh5225__ezDrvBAK.md - wiki/sources/descriptions/gmh5225__executor.md - wiki/sources/descriptions/dmaivel__ntoseye.md - wiki/sources/descriptions/c4kef__UAC.md - wiki/sources/descriptions/can1357__NtLua.md - wiki/sources/descriptions/cansarigol__pdbr.md - wiki/sources/descriptions/diversenok__DiaSymbolView.md - wiki/sources/descriptions/donnaskiez__ac.md - wiki/sources/descriptions/donnaskiez__nmi-callback-handler.md - wiki/sources/descriptions/dretax__GarHal_CSGO.md - wiki/sources/descriptions/dumbasPL__fumo_loader.md - wiki/sources/descriptions/gmh5225__External-Dayz-Cheat.md - wiki/sources/descriptions/gmh5225__inline-syscall.md - wiki/sources/descriptions/JustasMasiulis__inline_syscall.md - wiki/sources/descriptions/gmh5225__Interep-Driver-Leak.md - wiki/sources/descriptions/gmh5225__kli-ex.md - wiki/sources/descriptions/gmh5225__kernel-callback-functions-list.md - wiki/sources/descriptions/gmh5225__job_communication.md - wiki/sources/descriptions/gmh5225__NlsCodeInjectionThroughRegistry.md - wiki/sources/descriptions/gmh5225__NullDriverCheat.md - wiki/sources/descriptions/gmh5225__NtRays.md - wiki/sources/descriptions/gmh5225__NtUserInjectMouseInput-syscall.md - wiki/sources/descriptions/ZoondEngine__NoBastian_v2.md - wiki/sources/descriptions/Zpes__mouse-input-injection.md - wiki/sources/descriptions/M3351AN__mouse_input_injection.md - wiki/sources/descriptions/M3351AN__Samidare.md - wiki/sources/descriptions/M3351AN__UkiaRPM.md - wiki/sources/descriptions/M3351AN__Usugumo.md - wiki/sources/descriptions/M3351AN__ZhangBing-Injector.md - wiki/sources/descriptions/3a1__Zodiak.md - wiki/sources/descriptions/3nolan5__R5Apex-UserMode.md - wiki/sources/descriptions/M1fisto__nullptr-apex-external.md - wiki/sources/descriptions/gmh5225__NVDrv.md - wiki/sources/descriptions/huntandhackett__process-cloning.md - wiki/sources/descriptions/hLunaaa__hLunaaa.github.io.md - wiki/sources/descriptions/Aki2k__BEDaisy.md - wiki/sources/descriptions/huoji120__goodeye.md - wiki/sources/descriptions/hubblo-org__windows-rapl-driver.md - wiki/sources/descriptions/huoji120__Etw-Syscall.md - wiki/sources/descriptions/hasherezade__thread_namecalling.md - wiki/sources/descriptions/h4sh5__DumpIt-mirror.md - wiki/sources/descriptions/gmh5225__Tool-DIYSystemMemoryDump.md - wiki/sources/descriptions/gmh5225__OfflineCrashDumpUefi.md - wiki/sources/descriptions/heeeyaaaa__vmem-decrypt.md - wiki/sources/descriptions/hotline1337__umium.md - wiki/sources/descriptions/hugsy__ropgadget-rs.md - wiki/sources/descriptions/hugsy__CFB.md - wiki/sources/descriptions/wesmar__WinDefCtl.md - wiki/sources/descriptions/mattifestation__WDACTools.md - wiki/sources/descriptions/qtkite__defender-control.md - wiki/sources/descriptions/wesmar__VaultGuard.md - wiki/sources/descriptions/wesmar__KeyboardKit.md - wiki/sources/descriptions/vsaint1__kernel-mouse.md - wiki/sources/descriptions/wesmar__KernelResearchKit.md - wiki/sources/descriptions/wesmar__BootBypass.md - wiki/sources/descriptions/rabbitstack__fibratus.md - wiki/sources/descriptions/progmboy__openprocmon.md - wiki/sources/descriptions/rad9800__BootExecuteEDR.md - wiki/sources/descriptions/utoni__PastDSE.md - wiki/sources/descriptions/wesmar__EfiTool.md - wiki/sources/descriptions/wesmar__UnderVolter.md - wiki/sources/descriptions/wesmar__NTFS_EFI.md - wiki/sources/descriptions/wesmar__CmdT.md - wiki/sources/descriptions/weak1337__EvCommunication.md - wiki/sources/descriptions/weak1337__DetectTpmSpoofing.md - wiki/sources/descriptions/fsquirt__SEWindows.md - wiki/sources/descriptions/synctop__tpm-mmio.md - wiki/sources/descriptions/s0ngidong3__TPM-SPOOFER.md - wiki/sources/descriptions/SamuelTulach__rainbow.md - wiki/sources/descriptions/SamuelTulach__tpm-spoofer.md - wiki/sources/descriptions/SamuelTulach__negativespoofer.md - wiki/sources/descriptions/SamuelTulach__PwnedBoot.md - wiki/sources/descriptions/AlSch092__UltimateAntiCheat.md - wiki/sources/descriptions/AlSch092__EasyHandles.md - wiki/sources/descriptions/Alex3434__wmi-static-spoofer.md - wiki/sources/descriptions/SamuelTulach__mutante.md - wiki/sources/descriptions/SamuelTulach__meme-rw.md - wiki/sources/descriptions/SamuelTulach__efi-memory.md - wiki/sources/descriptions/Mattiwatti__EfiGuard.md - wiki/sources/descriptions/SamuelTulach__eac_cr3_shuffle.md - wiki/sources/descriptions/SamuelTulach__HookGuard.md - wiki/sources/descriptions/wbenny__injdrv.md - wiki/sources/descriptions/wbenny__KSOCKET.md - wiki/sources/descriptions/MiroKaku__libwsk.md - wiki/sources/descriptions/wbaby__DoubleCallBack.md - wiki/sources/descriptions/cs1ime__KernelDwm.md - wiki/sources/descriptions/wazuh__wazuh.md - wiki/sources/descriptions/TheHive-Project__TheHive.md - wiki/sources/descriptions/waryas__xign_poc_april_2026.md - wiki/sources/descriptions/w1u0u1__kinject.md - wiki/sources/descriptions/sum-catnip__kptnhook.md - wiki/sources/descriptions/volatilityfoundation__volatility3.md - wiki/sources/descriptions/volatilityfoundation__volatility.md - wiki/sources/descriptions/evild3ad__MemProcFS-Analyzer.md - wiki/sources/descriptions/eversinc33__unKover.md - wiki/sources/descriptions/eversinc33__drvtrace.md - wiki/sources/descriptions/VirtualBox__virtualbox.md - wiki/sources/descriptions/VoidSec__ioctlpus.md - wiki/sources/descriptions/vmi-rs__ephemera.md - wiki/sources/descriptions/tasox__miniDumpReader.md - wiki/sources/descriptions/skelsec__minidump.md - wiki/sources/descriptions/0vercl0k__udmp-parser.md - wiki/sources/descriptions/0vercl0k__kdmp-parser.md - wiki/sources/descriptions/0vercl0k__symbolizer.md - wiki/sources/descriptions/0vercl0k__snapshot.md - wiki/sources/descriptions/b4rtik__ATPMiniDump.md - wiki/sources/descriptions/Adepts-Of-0xCC__MiniDumpWriteDumpPoC.md - wiki/sources/descriptions/libyal__libmdmp.md - wiki/sources/descriptions/mrexodia__dumpulator.md - wiki/sources/descriptions/momo5502__sogen.md - wiki/sources/descriptions/momo5502__hypervisor.md - wiki/sources/descriptions/mojtabafalleh__emulator.md - wiki/sources/descriptions/mrexodia__TitanHide.md - wiki/sources/descriptions/mrexodia__NtPhp.md - wiki/sources/descriptions/mrexodia__EfiCMake.md - wiki/sources/descriptions/misc0110__PTEditor.md - wiki/sources/descriptions/shareef12__cpuz.md - wiki/sources/descriptions/SamLarenN__CPUZ-DSEFix.md - wiki/sources/descriptions/sina85__hide-file.md - wiki/sources/descriptions/zensenzay__memfilter-fn-driver-.md - wiki/sources/descriptions/mein-0__forti-research.md - wiki/sources/descriptions/KeServiceDescriptorTable__vulnerable-drivers.md - wiki/sources/descriptions/KeServiceDescriptorTable__cormem.sys-vulnerable-driver.md - wiki/sources/descriptions/KeServiceDescriptorTable__roak.md - wiki/sources/descriptions/KDIo3__PCIBan.md - wiki/sources/descriptions/KANKOSHEV__Detect-HiddenThread-via-KPRCB.md - wiki/sources/descriptions/KANKOSHEV__Detect-KeAttachProcess.md - wiki/sources/descriptions/KANKOSHEV__Detect-MouseClassServiceCallback.md - wiki/sources/descriptions/KANKOSHEV__face-injector-v2.md - wiki/sources/descriptions/KGB-1337__memmap.md - wiki/sources/descriptions/Kharos102__IOCTLDump.md - wiki/sources/descriptions/K-cazb__pubg-public.md - wiki/sources/descriptions/KaylinOwO__Project-Branthium.md - wiki/sources/descriptions/KelvinMsft__PerfMon.md - wiki/sources/descriptions/KelvinMsft__ThreadSpy.md - wiki/sources/descriptions/KelvinMsft__UsbMon.md - wiki/sources/descriptions/KelvinMsft__NoTruth.md - wiki/sources/descriptions/KiFilterFiberContext__windows-software-policy.md - wiki/sources/descriptions/Kudaes__Dumpy.md - wiki/sources/descriptions/Kudaes__Puzzle.md - wiki/sources/descriptions/zensenzay__wnf-driver-meme.md - wiki/sources/descriptions/nbqofficial__HideDriver.md - wiki/sources/descriptions/ExpLife0011__HideDriver.md - wiki/sources/descriptions/EquiFox__KsDumper.md - wiki/sources/descriptions/EBalloon__Common-Registry.md - wiki/sources/descriptions/EBalloon__MapPage.md - wiki/sources/descriptions/EBalloon__Remap.md - wiki/sources/descriptions/EBalloon__MmCopyMemory.md - wiki/sources/descriptions/EvilBytecode__Ebyte-Syscalls.md - wiki/sources/descriptions/EvilBytecode__GhostVEH.md - wiki/sources/descriptions/EvilBytecode__IDontLikeFileLocks.md - wiki/sources/descriptions/EvilBytecode__CustomDpapi.md - wiki/sources/descriptions/gmh5225__HideDriverTesting.md - wiki/sources/descriptions/kitty8904__blanket.md - wiki/sources/descriptions/jthuraisamy__TelemetrySourcerer.md - wiki/sources/descriptions/jxy-s__herpaderping.md - wiki/sources/descriptions/jxy-s__vfdynf.md - wiki/sources/descriptions/juniorjacob__readwrite-kernel-stable.md - wiki/sources/descriptions/vmcall__owned_alignment.md - wiki/sources/descriptions/vergamota__KslKatz.md - wiki/sources/descriptions/andreisss__KslDump.md - wiki/sources/descriptions/unkvolism__Solemn.md - wiki/sources/descriptions/un4ckn0wl3z__dioprocess-private.md - wiki/sources/descriptions/thetuh__anticheat-poc.md - wiki/sources/descriptions/PatchRequest__PeregrineAntiCheat.md - wiki/sources/descriptions/thexin7__kernel-cve-analysis.md - wiki/sources/descriptions/noahware__darken-anticheat.md - wiki/sources/descriptions/gmh5225__AntiCheat.md - wiki/sources/descriptions/gmh5225__AntiCheat-chrysalis.md - wiki/sources/descriptions/thesecretclub__window_hijack.md - wiki/sources/descriptions/gmh5225__WindowProtect.md - wiki/sources/descriptions/thesecretclub__callout-poc.md - wiki/sources/descriptions/thalium__ida_kmdf.md - wiki/sources/descriptions/tandasat__Sushi.md - wiki/sources/descriptions/tandasat__MiniVisorPkg.md - wiki/sources/descriptions/synacktiv__windows_kernel_shadow_stack.md - wiki/sources/descriptions/gmh5225__QueryShadowStack.md - wiki/sources/descriptions/gmh5225__CET-win10.md - wiki/sources/descriptions/gmh5225__PsNotifRoutineUnloader.md - wiki/sources/descriptions/symeonp__Lenovo-CVE-2025-8061.md - wiki/sources/descriptions/sxlmnwb__windows-subsystem-linux.md - wiki/sources/descriptions/microsoft__WSL2-Linux-Kernel.md - wiki/sources/descriptions/microsoft__WSL.md - wiki/sources/descriptions/Nevuly__WSL2-Linux-Kernel-Rolling.md - wiki/sources/descriptions/k3v1n1990s__docker-win.md - wiki/sources/descriptions/svnscha__mcp-windbg.md - wiki/sources/descriptions/Deputation__hygieia.md - wiki/sources/descriptions/DejavuSecure__DetectNtoskrnlIntegrity.md - wiki/sources/descriptions/DSecurity__efiSeek.md - wiki/sources/descriptions/DeiVid-12__SmKernel-CSGO.md - wiki/sources/descriptions/Devolutions__windbg-tool.md - wiki/sources/descriptions/DenuvoSoftwareSolutions__Onlooker.md - wiki/sources/descriptions/DumpAnalysis__WinDbg_Copilot.md - wiki/sources/descriptions/0xeb__windbg-copilot.md - wiki/sources/descriptions/Dump-GUY__IDA_PHNT_TYPES.md - wiki/sources/descriptions/kernullist__windbg-decompile-ext.md - wiki/sources/descriptions/kernullist__kn-live-dbg.md - wiki/sources/descriptions/keowu__koidbg.md - wiki/sources/descriptions/ioncodes__pooldump.md - wiki/sources/descriptions/kernullist__kn-diff-pool.md - wiki/sources/descriptions/kernullist__kernforge.md - wiki/sources/descriptions/kernelwernel__VMAware.md - wiki/sources/descriptions/supermanc88__Document.md - wiki/sources/descriptions/stuxnet147__PiDqSerializationWrite-Example.md - wiki/sources/descriptions/stuxnet147__Known-Driver-Mappers.md - wiki/sources/descriptions/stdhu__windows-kernel-pagehook.md - wiki/sources/descriptions/Xacone__Eneio64-Driver-Exploit.md - wiki/sources/descriptions/XaFF-XaFF__BugcheckSuppressor.md - wiki/sources/descriptions/Xyrem__Yumekage.md - wiki/sources/descriptions/Xxmmy__vulnerable-driver-scanner.md - wiki/sources/descriptions/Systemhaus-Schulz__DriverRiskScout.md - wiki/sources/descriptions/FourCoreLabs__LolDriverScan.md - wiki/sources/descriptions/snare__ida-efiutils.md - wiki/sources/descriptions/sapdragon__syscalls-cpp.md - wiki/sources/descriptions/sbsbsbssbsbs__boundcallback.md - wiki/sources/descriptions/Staatsgeheim__PsImageNotifyRoutineSpamFilter.md - wiki/sources/descriptions/SurgeGotTappedAgain__Pink-Eye.md - wiki/sources/descriptions/StephanvanSchaik__windows-kernel-rs.md - wiki/sources/descriptions/saileaxh__iida-mcp.md - wiki/sources/descriptions/sai2fast__DsArk64.md - wiki/sources/descriptions/sa413x__UEFI-Bootloader.md - wiki/sources/descriptions/ryan-weil__ReadWriteDriver.md - wiki/sources/descriptions/R4YVEN__raybot-zero.md - wiki/sources/descriptions/RomanRybachek__Copy_RVA.md - wiki/sources/descriptions/Rythorndoran__enum_real_dirbase.md - wiki/sources/descriptions/Rwkeith__Diglett.md - wiki/sources/descriptions/Rwkeith__Nomad.md - wiki/sources/descriptions/Rythorndoran__PageTableHook.md - wiki/sources/descriptions/Rantanen__ghidra-minidump-loader.md - wiki/sources/descriptions/RavenOfTime__Apex-Legends-Esp.md - wiki/sources/descriptions/rogxo__ReadPhys.md - wiki/sources/descriptions/rogerxiii__kernel-codecave-poc.md - wiki/sources/descriptions/TheCruZ__EFI_Driver_Access.md - wiki/sources/descriptions/TheCruZ__Apex_Legends_Driver_Cheat.md - wiki/sources/descriptions/TheCruZ__Direct-EFI-Apex-Cheat.md - wiki/sources/descriptions/TheCruZ__kdmapper.md - wiki/sources/descriptions/Brattlof__kdmapper-1909.md - wiki/sources/descriptions/eddeeh__kdmapper.md - wiki/sources/descriptions/rmccrystal__kdmapper-rs.md - wiki/sources/descriptions/paysonism__saturn-mapper.md - wiki/sources/descriptions/paradoxwastaken__Poseidon.md - wiki/sources/descriptions/rhboot__pesign.md - wiki/sources/descriptions/mihaly044__pedigest.md - wiki/sources/descriptions/michaelmsonne__SignToolGUI.md - wiki/sources/descriptions/hzqst__FuckCertVerifyTimeValidity.md - wiki/sources/descriptions/Jemmy1228__HookSigntool.md - wiki/sources/descriptions/J0xna__Kernel-Overlay-Hider.md - wiki/sources/descriptions/JGonz1337__kernel-eac-be-injector.md - wiki/sources/descriptions/JGonz1337__kernel-eac-be-comm.md - wiki/sources/descriptions/Jamesits__BGRTInjector.md - wiki/sources/descriptions/JKornev__cfgdump.md - wiki/sources/descriptions/JKornev__hidden.md - wiki/sources/descriptions/mathisvickie__sign-expired.md - wiki/sources/descriptions/mtrojnar__osslsigncode.md - wiki/sources/descriptions/namazso__MagicSigner.md - wiki/sources/descriptions/repnz__apc-research.md - wiki/sources/descriptions/redteamfortress__PhantomKiller.md - wiki/sources/descriptions/namazso__physmem_drivers.md - wiki/sources/descriptions/rbmm__KPDB.md - wiki/sources/descriptions/GetRektBoy724__KPDB.md - wiki/sources/descriptions/r0keb__Smep-Bypass.md - wiki/sources/descriptions/orinimron123__CVE-2026-40369-EXPLOIT.md - wiki/sources/descriptions/nu1lptr0__CVE-2025-21333.md - wiki/sources/descriptions/gmh5225__CVE-2024-35250.md - wiki/sources/descriptions/gmh5225__CVE-2024-26229.md - wiki/sources/descriptions/gmh5225__CVE-2024-21338.md - wiki/sources/descriptions/MrAle98__ATDCM64a-LPE.md - wiki/sources/descriptions/MrAle98__CVE-2024-49138-POC.md - wiki/sources/descriptions/Mr-Un1k0d3r__AMSI-ETW-Patch.md - wiki/sources/descriptions/gmh5225__CVE-2022-42046.md - wiki/sources/descriptions/gmh5225__CVE-2022-42045.md - wiki/sources/descriptions/gmh5225__CVE-2021-21551.md - wiki/sources/descriptions/gmh5225__CVE-2021-21551-POC.md - wiki/sources/descriptions/gmh5225__CVE-2022-3699.md - wiki/sources/descriptions/gmh5225__CVE-2025-21333-POC.md - wiki/sources/descriptions/originsec__pocsmith.md - wiki/sources/descriptions/olafhartong__BamboozlEDR.md - wiki/sources/descriptions/not-matthias__Nemesis.md - wiki/sources/descriptions/noahware__hyper-reV.md - wiki/sources/descriptions/noahware__apic.md - wiki/sources/descriptions/noahware__armcall.md - wiki/sources/descriptions/nlepleux__MappedCallback.md - wiki/sources/descriptions/nkga__cheat-driver.md - wiki/sources/descriptions/nbqofficial__norsefire.md - wiki/sources/descriptions/krispybyte__Simple-Rust-Base.md - wiki/sources/descriptions/krispybyte__Simple-EFT-Base.md - wiki/sources/descriptions/frankie-11__eft-external.md - wiki/sources/descriptions/fcancelog__EftStreamedCheat.md - wiki/sources/descriptions/frankelitoc__UE4-c-.md - wiki/sources/descriptions/gmh5225__ricochet-disabler.md - wiki/sources/descriptions/gmh5225__rust-external-1.md - wiki/sources/descriptions/gmh5225__Fortnite-External.md - wiki/sources/descriptions/gmh5225__Fortnite-External-Cheat-WinSense-Leak.md - wiki/sources/descriptions/gmh5225__Rust-Cheat-External.md - wiki/sources/descriptions/gmh5225__Rust-External-Source.md - wiki/sources/descriptions/gmh5225__Rust-ExternaL-and-Driver-AlienCheats.md - wiki/sources/descriptions/gmh5225__Rico-Cheat-rust-external.md - wiki/sources/descriptions/gmh5225__superpeople-client.md - wiki/sources/descriptions/gmh5225__titancf.md - wiki/sources/descriptions/gmh5225__UltraDriver-Game-Cheat.md - wiki/sources/descriptions/kouzhudong__AntiHook.md - wiki/sources/descriptions/kprprivate__EAC-CR3-BYPASS.md - wiki/sources/descriptions/konstantin89__windows-kernel-debugging-guide.md - wiki/sources/descriptions/gmh5225__ida_vmware_windows_gdb.md - wiki/sources/descriptions/kkpwn__ErisDbg.md - wiki/sources/descriptions/kkent030315__MsIoExploit.md - wiki/sources/descriptions/kkent030315__evil-mhyprot-cli.md - wiki/sources/descriptions/gmh5225__mhxy_kernel.md - wiki/sources/descriptions/gmh5225__manipulating_token.md - wiki/sources/descriptions/gmh5225__Map-file-in-system-space.md - wiki/sources/descriptions/gmh5225__mhxy.md - wiki/sources/descriptions/gmh5225__mhydeath.md - wiki/sources/descriptions/gmh5225__CVE-2015-2291.md - wiki/sources/descriptions/gmh5225__CVE-2017-9769.md - wiki/sources/descriptions/gmh5225__CVE-2018-19320.md - wiki/sources/descriptions/gmh5225__CVE-2018-19320-LPE.md - wiki/sources/descriptions/gmh5225__CVE-2020-14974.md - wiki/sources/descriptions/gmh5225__CVE-2020-36603.md - wiki/sources/descriptions/gmh5225__mhyprot2.md - wiki/sources/descriptions/gmh5225__Mhyprot2DrvControl.md - wiki/sources/descriptions/gmh5225__MSSymbolsCollection.md - wiki/sources/descriptions/gmh5225__MS-Vulnerable-Driver-List.md - wiki/sources/descriptions/gmh5225__evil-mhyprot-cli.md - wiki/sources/descriptions/gmh5225__Paladins-internal-Cheat.md - wiki/sources/descriptions/gmh5225__lenovo_mapper.md - wiki/sources/descriptions/gmh5225__imxyviMapper.md - wiki/sources/descriptions/U65535F__ThrottleStopPoC.md - wiki/sources/descriptions/CaledoniaProject__drivers-binaries.md - wiki/sources/descriptions/ChengChengCC__Ark-tools.md - wiki/sources/descriptions/CristiNacu__ingsoc.md - wiki/sources/descriptions/CyberSecurityUP__DriverVuln-Analyzer-IDA-Plugin.md - wiki/sources/descriptions/CyberSecurityUP__ViGEmBus-Driver-Exploitation.md - wiki/sources/descriptions/CyberSecurityUP__UrekMazino-Malware.md - wiki/sources/descriptions/UCFoxi__Shared-FlushFileBuffers-Communication.md - wiki/sources/descriptions/gmh5225__UCFoxi-Shared-FlushFileBuffers-Communication-Update.md - wiki/sources/descriptions/gmh5225__UCMapper.md - wiki/sources/descriptions/gmh5225__lenovo_exec.md - wiki/sources/descriptions/gmh5225__kur.md - wiki/sources/descriptions/gmh5225__LetMeGG.md - wiki/sources/descriptions/gmh5225__Handle-Ripper.md - wiki/sources/descriptions/gmh5225__LSASS-DumpThatLSASS.md - wiki/sources/descriptions/gmh5225__KExecDD.md - wiki/sources/descriptions/gmh5225__KexecDDPlus.md - wiki/sources/descriptions/gmh5225__Kernel_Anti-Cheat.md - wiki/sources/descriptions/Vasieco__Kernel-Anticheat.md - wiki/sources/descriptions/Valthrun__valthrun-uefi-mapper.md - wiki/sources/descriptions/TimMisiak__WinDbgCookbook.md - wiki/sources/descriptions/Twobot7__advanced-efi-driver-with-gdi-and-kernel-mouse-input.md - wiki/sources/descriptions/Valthrun__Valthrun.md - wiki/sources/descriptions/Valthrun__Valthrun_PUBG.md - wiki/sources/descriptions/gmh5225__KDP-compatible-driver-loader.md - wiki/sources/descriptions/gmh5225__KernelSnippets.md - wiki/sources/descriptions/gmh5225__Kernel-VAD-Injector.md - wiki/sources/descriptions/H3d9__sguard_limit.md - wiki/sources/descriptions/gmh5225__gdrv-loader.md - wiki/sources/descriptions/gmh5225__gdriver-lib.md - wiki/sources/descriptions/kkent030315__EQU8-PoC.md - wiki/sources/descriptions/hotline1337__equ8_bypass.md - wiki/sources/descriptions/hfiref0x__UPGDSED.md - wiki/sources/descriptions/hfiref0x__KDU.md - wiki/sources/descriptions/hfiref0x__SyscallTables.md - wiki/sources/descriptions/hfiref0x__NtCall64.md - wiki/sources/descriptions/holi4m__gdrv-loader-v2.md - wiki/sources/descriptions/1337kenzo__gdrv-loader-updated.md - wiki/sources/descriptions/9176324__Shark.md - wiki/sources/descriptions/AdamOron__PatchGuardBypass.md - wiki/sources/descriptions/AmitMoshel1__gdrv_sys_exploit.md - wiki/sources/descriptions/AmitMoshel1__PatchGuardEncryptorDriver.md - wiki/sources/descriptions/ANYLNK__NSecSoftBYOVD.md - wiki/sources/descriptions/nbqofficial__kernel-csgo.md - wiki/sources/descriptions/naorhaziz__irql.md - wiki/sources/descriptions/moiz-2x__CVE-2025-24990_POC.md - wiki/sources/descriptions/microsoft__pdblister.md - wiki/sources/descriptions/microsoft__pdb-rs.md - wiki/sources/descriptions/microsoft__SDCM.md - wiki/sources/descriptions/memflow__memflow-kvm.md - wiki/sources/descriptions/BishopTopG__all-about-eac.md - wiki/sources/descriptions/mastercodeon314__KsDumper-11.md - wiki/sources/descriptions/marcusbotacin__BranchMonitoringProject.md - wiki/sources/descriptions/libiht__libiht.md - wiki/sources/descriptions/intel__pcm.md - wiki/sources/descriptions/gmh5225__pmctrace.md - wiki/sources/descriptions/gmh5225__PMI-hpc.md - wiki/sources/descriptions/gmh5225__PDF-PMC-X86.md - wiki/sources/descriptions/intelpt__winipt.md - wiki/sources/descriptions/intelpt__processor-trace.md - wiki/sources/descriptions/intelpt__WindowsIntelPT.md - wiki/sources/descriptions/armasm__EasyAntiPatchGuard.md - wiki/sources/descriptions/armvirus__SinMapper.md - wiki/sources/descriptions/armvirus__DriverDllFInder.md - wiki/sources/descriptions/ashleyhung__WinRing0.md - wiki/sources/descriptions/australeo__libipt-rs.md - wiki/sources/descriptions/illegal-instruction-co__processhacker-mcp.md - wiki/sources/descriptions/lowleveldesign__comon.md - wiki/sources/descriptions/long123king__dk.md - wiki/sources/descriptions/linuxboot__fiano.md - wiki/sources/descriptions/kyxiaxiang__360WFP_Exploit.md - wiki/sources/descriptions/leap0x7b__luaboot.md - wiki/sources/descriptions/lauralex__OAC.md - wiki/sources/descriptions/magicsword-io__LOLDrivers.md - wiki/sources/descriptions/mandiant__ShimCacheParser.md - wiki/sources/descriptions/mactec0__Kernelmode-manual-mapping-through-IAT.md - wiki/sources/descriptions/kernelstub__Cognitor.md - wiki/sources/descriptions/jnastarot__HIGU_ntcall.md - wiki/sources/descriptions/jsecurity101__MSFT_DriverBlockList.md - wiki/sources/descriptions/Harvester57__CodeIntegrity-DriverBlocklist.md - wiki/sources/descriptions/jsacco__ntoskrnlwalker.md - wiki/sources/descriptions/jsacco__NTKernelWalkerLib.md - wiki/sources/descriptions/jonomango__nohv.md - wiki/sources/descriptions/jonny-jhnson__EtwWatcher.md - wiki/sources/descriptions/jdu2600__CFG-FindHiddenShellcode.md - wiki/sources/descriptions/jdu2600__EtwTi-FluctuationMonitor.md - wiki/sources/descriptions/jdu2600__Etw-SyscallMonitor.md - wiki/sources/descriptions/jlgreathouse__AMD_IBS_Toolkit.md - wiki/sources/descriptions/jackullrich__syscall-detect.md - wiki/sources/descriptions/adrianyy__rw_socket_driver.md - wiki/sources/descriptions/adspro15__km-um-communication.md - wiki/sources/descriptions/adspro15__DirectInput.md - wiki/sources/descriptions/alal4465__KernelMon.md - wiki/sources/descriptions/alfarom256__drivers_and_shit.md - wiki/sources/descriptions/alfarom256__rs-ldr.md - wiki/sources/descriptions/alexkrnl__Kernel-dll-injector.md - wiki/sources/descriptions/ajkhoury__pubg_internal.md - wiki/sources/descriptions/ajkhoury__UEFI-Bootkit.md - wiki/sources/descriptions/ait-aecid__rootkit-detection-ebpf-time-trace.md - wiki/sources/descriptions/jakobfriedl__usb-monitor-bof.md - wiki/sources/descriptions/isiddique2024__Page-Table-Injector.md - wiki/sources/descriptions/iss4cf0ng__OpenPetya.md - wiki/sources/descriptions/isoadam__gina_public.md - wiki/sources/descriptions/jimbeveridge__readdirectorychanges.md - wiki/sources/descriptions/google__android-emulator-hypervisor-driver.md - wiki/sources/descriptions/google__grr.md - wiki/sources/descriptions/gmh5225__win32k_file_collection.md - wiki/sources/descriptions/gmh5225__win32k_file_collection2.md - wiki/sources/descriptions/GetRektBoy724__Win32kHooker.md - wiki/sources/descriptions/GetRektBoy724__DCMB.md - wiki/sources/descriptions/gmh5225__ntoskrnl_file_collection.md - wiki/sources/descriptions/gmh5225__hv-detect.md - wiki/sources/descriptions/gmh5225__Go-Detection-Hyper-v.md - wiki/sources/descriptions/gmh5225__Detection-Hyper-v.md - wiki/sources/descriptions/gmh5225__Detect-Hypervisor_detect_ring_0.md - wiki/sources/descriptions/gmh5225__Detection-CheatEngine-Ring0.md - wiki/sources/descriptions/gmh5225__vt-debuger.md - wiki/sources/descriptions/gmh5225__zam64-zemina.md - wiki/sources/descriptions/gmh5225__vdk.md - wiki/sources/descriptions/gmh5225__s4killer.md - wiki/sources/descriptions/gmh5225__S4Mapper.md - wiki/sources/descriptions/gmh5225__razer-rzctl.md - wiki/sources/descriptions/gmh5225__qiomem.md - wiki/sources/descriptions/gmh5225__nullmap.md - wiki/sources/descriptions/gmh5225__pdfwkrnl-exploit.md - wiki/sources/descriptions/gmh5225__PdFwKrnlMapper.md - wiki/sources/descriptions/gmh5225__r69-driver.md - wiki/sources/descriptions/gmh5225__r0ak.md - wiki/sources/descriptions/guidoreina__minivers.md - wiki/sources/descriptions/jiubanlo__WinNT5_src_20201004.md - wiki/sources/descriptions/not1cyyy__Anti-Cheat-Amateur.md - wiki/sources/descriptions/not1cyyy__PowerVM.md - wiki/sources/descriptions/irql__nokd.md - wiki/sources/descriptions/hkx3upper__Karlann.md - wiki/sources/descriptions/gmh5225__ampa.sys-exp.md - wiki/sources/descriptions/gmh5225__amd-ryzen-master-driver-v17-exploit.md - wiki/sources/descriptions/gmh5225__BadRentdrv2.md - wiki/sources/descriptions/gmh5225__Voyager.md - wiki/sources/descriptions/gmh5225__VanderLeague.md - wiki/sources/descriptions/gmh5225__VulnerableKernel_Driver.md - wiki/sources/descriptions/gmh5225__VulnerablePatchGuardExploit.md - wiki/sources/descriptions/gmh5225__QuickPGTrigger.md - wiki/sources/descriptions/gmh5225__Patchguard-2023.md - wiki/sources/descriptions/Neo23x0__Raccine.md - wiki/sources/descriptions/NeoMaster831__kurasagi.md - wiki/sources/descriptions/gmh5225__Win-Driver-EXP.md - wiki/sources/descriptions/gmh5225__WatchDogKiller.md - wiki/sources/descriptions/gmh5225__Terminator.md - wiki/sources/descriptions/EvilBytecode__EDR-XDR-AV-Killer.md - wiki/sources/descriptions/gmh5225__Practical-Reverse-Engineering-Solutions.md - wiki/sources/descriptions/gmh5225__ProcessKiller-BYOVD.md - wiki/sources/descriptions/Muz1K1zuM__PoisonKiller_bof.md - wiki/sources/descriptions/gmh5225__Killer.md - wiki/sources/descriptions/gmh5225__Killer-Exercice.md - wiki/sources/descriptions/gmh5225__PPLKiller.md - wiki/sources/descriptions/2x7EQ13__CreateProcessAsPPL.md - wiki/sources/descriptions/gmh5225__TS-Fucker.md - wiki/sources/descriptions/gmh5225__SpeedFan-Exploit.md - wiki/sources/descriptions/gmh5225__OpenHardwareMonitor-PoC.md - wiki/sources/descriptions/gmh5225__HPHardwareDiagnostics-PoC.md - wiki/sources/descriptions/gmh5225__HITCON-2023-Demo-CVE-2023-20562.md - wiki/sources/descriptions/gmh5225__RTCore64_Vulnerability.md - wiki/sources/descriptions/gmh5225__Windows-10-22H2-Vulnerable-driver-communication.md - wiki/sources/descriptions/changeofpace__MouHidInputHook.md - wiki/sources/descriptions/ch3rn0byl__ANTfs.md - wiki/sources/descriptions/ch3rn0byl__WinDbg-Extensions.md - wiki/sources/descriptions/andrew-hoffman__ghidra-vxd-tools.md - wiki/sources/descriptions/anhkgg__awesome-windbg-extensions.md - wiki/sources/descriptions/allogic__KDBG.md - wiki/sources/descriptions/bruce30262__TWindbg.md - wiki/sources/descriptions/poli0981__wardsweep.md - wiki/sources/descriptions/YouNeverKnow00__Kernelmode-DLL-Injector.md - wiki/sources/descriptions/LabGuy94__Diskjacker.md - wiki/sources/descriptions/ContionMig__LSASS-Usermode-Bypass.md - wiki/sources/descriptions/Compiled-Code__eac-mapper.md - wiki/sources/descriptions/ComodoSecurity__openedr.md - wiki/sources/descriptions/0xrawsec__whids.md - wiki/sources/descriptions/0xf1a__DSMM.md - wiki/sources/descriptions/0xflux__Sanctum.md - wiki/sources/descriptions/0xjbb__EyYoEtwWhereYouAt.md - wiki/sources/descriptions/Cr4sh__s6_pcie_microblaze.md - wiki/sources/descriptions/Cr4sh__pico_dma.md - wiki/sources/descriptions/Cr4sh__SmmBackdoorNg.md - wiki/sources/descriptions/Cr4sh__KernelForge.md - wiki/sources/descriptions/DownWithUp__CallMon.md - wiki/sources/descriptions/0xcpu__WinAltSyscallHandler.md - wiki/sources/descriptions/0xDbgMan__DrvEye.md - wiki/sources/descriptions/0xPrimo__KMDllInjector.md - wiki/sources/descriptions/0xJs__BYOVD_read_write_primitive.md - wiki/sources/descriptions/0xJs__BYOVD_EDRKiller.md - wiki/sources/descriptions/0xGREG__registry-callbacks.md - wiki/sources/descriptions/Dor00tkit__BamExtensionTableHook.md - wiki/sources/descriptions/D3DXVECTOR2__NtUserUpdateWindowTrackingInfo.md - wiki/sources/descriptions/Chase1803__UCMiraka-ValorantExternal.md - wiki/sources/descriptions/DProvinciani__pt-detector.md - wiki/sources/descriptions/D4stiny__PeaceMaker.md - wiki/sources/descriptions/ApexLegendsUC__anti-cheat-emulator.md - wiki/sources/descriptions/Ahora57__MAJESTY-technologies.md - wiki/sources/descriptions/Air14__HyperHide.md - wiki/sources/descriptions/Air14__KDBGDecryptor.md - wiki/sources/descriptions/416rehman__DeepZero.md - wiki/sources/descriptions/4d61726b__VirtualKD-Redux.md updated: 2026-09-14 confidence: high --- # Windows Kernel Analyze Windows driver trust, callbacks, IRQL, kernel memory, DSE, PatchGuard, VBS/HVCI, ETW, crash evidence, and build-specific internals for authorized game-security research. Match undocumented structures, offsets, globals, and allocator behavior to the exact Windows build and symbols; separate documented contracts, observed state, and inference via [[kernel-evidence-baseline]]. (source: wiki/sources/skills/windows-kernel.md) ## Topic routing | Question lane | Route | |---------------|-------| | Driver surfaces, DSE, PatchGuard, VBS/HVCI, Secure Boot, symbol walking | [[driver-trust-boundaries]], [[patchguard]], [[hvci]]; trust-feature sub-areas below | | Callbacks, IRQL, APCs, driver IOCTL, hooking, ETW | [[kernel-callbacks]], [[etw-threat-intelligence]], [[driver-communication]] | | Pool architecture, memory access, dumps, load forensics | [[kernel-pool-scanning]], [[memory-acquisition-path]] | | Vulnerable drivers, boot/EFI threats, hypervisor defenses | [[byovd]], boot-trust and hypervisor sub-areas below | | Device-originated memory access (PCIe FPGA, bus master) | [[overviews/dma-attack]], [[dma]], [[iommu]] | | Build/symbol/version-sensitive conclusions | [[kernel-evidence-baseline]], [[research-rigor]] | | README resource selection for kernel lanes | [[resource-selection]], [[repository-navigation]] | Use sibling skill topics when one boundary dominates the question; apply [[research-rigor]] before turning PoCs, pool parsers, or callback bypass claims into findings. (source: wiki/sources/skills/windows-kernel.md) ## Driver trust boundaries and evidence Classify the host boundary before IOCTL, callback, or pool conclusions: device ACLs, per-operation authorization, driver provenance, and whether signed code still exposes unsafe interfaces. Use [[driver-trust-boundaries]] for the threat-model synthesis; actual reachability needs build/configuration evidence. For acquisition relayed over USB or network, apply [[memory-acquisition-path]] initiator/transport separation from [[overviews/dma-attack]] — legitimate incident response can produce the same acquisition artifacts. Review buffer lengths, output initialization, object lifetime, cancellation, and **IRQL** alongside caller authorization. **VBS/[[hvci]]:** distinguish capability, configuration, and **running state**; Memory Integrity compatibility does not prove every driver interface is safe. **Driver blocklists** have incomplete coverage — separate controls that prevent writing a vulnerable driver to disk from policies that block loading it, and record the active policy version rather than assuming protection from the OS name alone. Use Driver Verifier on a recovery-capable lab host when evaluating owned drivers; preserve tested configuration and crash artifacts — it can deliberately bugcheck and does not establish a low false-positive anti-abuse detector. (source: wiki/sources/skills/windows-kernel.md) ## Hypervisor and pool evidence limits Trusted hypervisors can enforce separate guest-memory protection boundaries, but protecting selected data differs from validating kernel code or preserving detector end-to-end coverage. See [[hvci]] for VTL0/VTL1 Memory Integrity and the review questions for hypervisor protection claims. **WHP** user-mode APIs manage guest partitions without granting arbitrary control over the running host kernel — correlate documented exit reasons and capabilities with the analysis question; a successful guest stop is not complete instruction tracing or deterministic replay. (source: wiki/sources/skills/windows-kernel.md) [[kernel-pool-scanning]] covers Segment Heap forensics; pair pool-tag leads with provenance — tags are attribution hints, not cryptographic driver identities. Internal tables such as `PiDDBCacheTable` require exact-build definitions, collection method, retention limits, and supporting artifacts before driver-history claims. (source: wiki/sources/skills/windows-kernel.md) ## Key sub-areas - **User-mode kernel symbol walking:** load local `ntoskrnl.exe`, resolve RVAs/types via dbghelp + Microsoft symbol server (`srv*cache*https://msdl.microsoft.com/download/symbols`), query struct field offsets programmatically, and scan executable sections for short ROP gadgets — reduces hardcoded-offset fragility when mapping EPROCESS/ETHREAD/token fields or evaluating exploit mitigations. Historical NT5-era ground-truth reference via [[winnt5-src-20201004]] (leaked Windows 2000/XP/Server 2003 source tree; `NT/` base/drivers/windows/net/shell; kernel/Win32/subsystem implementation study) complements symbol-walking tools when researching legacy NT internals. (source: wiki/sources/descriptions/jiubanlo__WinNT5_src_20201004.md) Windows 9x VxD (Virtual Device Driver) Ghidra annotation via [[ghidra-vxd-tools]] (Jython; INT 20h VxDCall decode against VMDisp9x vmm.h database; VMM debug-string/flag-word comments; legacy kernel-mode driver RE including historical game protection; Windows9x script category) covers pre-NT driver triage in the same lane. (source: wiki/sources/descriptions/andrew-hoffman__ghidra-vxd-tools.md) Build-target offset/gadget/symbol resolution via [[ntoskrnlwalker]] (automates ntoskrnl structure navigation for cheat / RE workflows) (source: wiki/sources/descriptions/jsacco__ntoskrnlwalker.md). Embeddable library form via [[ntkernelwalkerlib]] (dbghelp symbol RVAs + executable-section ROP gadget scan; cheat / kernel explorer) (source: wiki/sources/descriptions/jsacco__NTKernelWalkerLib.md). PHNT/SDK struct layout browser via [[bb]] (Benowin Blanc; libclang parse; WinDbg `dt`-like struct/enum/constant output without live attach; CLI+TUI+JSON export; Cheat → Windows kernel explorer) (source: wiki/sources/descriptions/cristeigabriela__bb.md). Web UI for [[bb]] dataset output via [[bb-viewer]] (ntoskrnl/hal functions, types, constants, IRQL annotations, type-relationship graphs; search/filter; user/kernel; amd64/x86/arm/arm64 switch; cheat / Windows kernel explorer) (source: wiki/sources/descriptions/cristeigabriela__bb-viewer.md). IDA type-library import for PHNT Native API structs/prototypes via [[ida-phnt-types]] (Dump-GUY; generated TIL + IDC from modern Windows SDK/PHNT; idaclang/tilib; 32/64-bit; driver and anti-cheat component RE) (source: wiki/sources/descriptions/Dump-GUY__IDA_PHNT_TYPES.md). General-purpose cross-format ROP gadget discovery via [[ropgadget-rs]] (Rust; parallel PE/ELF/Mach-O scan for ret-terminated chains; exploit-development / mitigation-evaluation lane beside build-specific ntoskrnl walkers) (source: wiki/sources/descriptions/hugsy__ropgadget-rs.md). Bulk manifest prep for offline symbol pulls via [[pdblister]] (Rust; PE debug-directory scan → symchk /om-style manifests + Symbol Server URLs; blocking/async download) (source: wiki/sources/descriptions/microsoft__pdblister.md). Pre-downloaded Microsoft kernel debug symbol (PDB) corpus via [[mssymbolscollection]] (gmh5225; ntoskrnl, CI.dll, and other kernel-mode binaries; Kernel Symbols category—offline cache beside Symbol Server pulls) (source: wiki/sources/descriptions/gmh5225__MSSymbolsCollection.md). Cross-build PE symbol/type/syscall database browser via [[windiff]] (Rust CLI + Next.js web UI; Winbindex PE fetch + Symbol Server PDB extraction → gzip JSON; Browse/Diff across OS builds for kernel and usermode binaries; EDR/anti-cheat surface research) (source: wiki/sources/descriptions/ergrelet__windiff.md). Pre-collected multi-build **ntoskrnl** binary corpora such as [[ntoskrnl-file-collection]] (gmh5225; version-diff reference corpus for kernel RE—not a turnkey analyzer) reduce corpus-gathering friction beside symbol-walking tooling. Live kernel memory inspection via [[ntoskrnl-viewer]] (IcEy-999; C/C++ custom driver + user-mode client; WinDbg-like `db`/`dw`/`dd`/`dq`/`d`/`x` commands; symbol or address reads including exported/unexported kernel symbols; x64; kernel RE / troubleshooting / Windows internals study) (source: wiki/sources/descriptions/IcEy-999__Ntoskrnl_Viewer.md). (source: wiki/sources/descriptions/gmh5225__ntoskrnl_file_collection.md) (source: wiki/sources/skills/windows-kernel.md) - **User-mode exception dispatch:** ntdll **`KiUserExceptionDispatcher`** hook research such as [[ki-user-exception-dispatcher-hook]] (brew02; C++; patch `Wow64PrepareForException` pointer in ntdll `.mrdata` via `LdrProtectMrdata`; Zydis dynamic pointer locate; avoids VEH chain manipulation; stealth UM exception hook study) (source: wiki/sources/descriptions/brew02__KiUserExceptionDispatcherHook.md); direct VEH chain registration via [[ghostveh]] (EvilBytecode; C++ PoC; locate `LdrpVectorHandlerList` in ntdll; `RtlEncodePointer`/`RtlDecodePointer` obfuscation; `LdrProtectMrdata` MRDATA unlock; bypasses `RtlAddVectoredExceptionHandler`; VEH internals / anti-debug / exception-handler manipulation research) (source: wiki/sources/descriptions/EvilBytecode__GhostVEH.md) - **Kernel licensing / policy path:** [[windows-software-policy]] (KiFilterFiberContext; documents `SystemPolicyInformation` `NtQuerySystemInformation` class; user-mode licensing components ↔ kernel policy driver; where policy data is handled; C source/headers + Python binary helper; Windows internals / software protection RE) (source: wiki/sources/descriptions/KiFilterFiberContext__windows-software-policy.md) - **AC driver runtime logger:** [[badlion-logger]] (KiFilterFiberContext; PoC kernel logger; IAT hooks during image-load callbacks; black-box monitoring of VMProtect-virtualized AC driver module; C++; educational driver instrumentation—not production-hardened) (source: wiki/sources/descriptions/KiFilterFiberContext__BadlionLogger.md) - **User-mode ntdll unhooking:** Rust tool/library [[nt-unhooker]] (Teach2Breach; inline/IAT hook state analysis; in-memory vs clean reference PE compare; symbol-based clean DLL retrieval; restore modified regions with safety checks; CLI + programmatic API; malware analysis / red team / defender hook-tampering study) (source: wiki/sources/descriptions/Teach2Breach__nt_unhooker.md) - **User-mode hook detection:** GUI tool [[hook-detector]] (0x6461726B; C++20; scans loaded modules/processes for inline/IAT hooks; remote PE parsing + manual PEB traversal vs expected executable layouts; DX11/ImGui; x86/x64; anti-cheat / RE hook-tampering inspection) (source: wiki/sources/descriptions/0x6461726B__Hook-Detector.md) - **KnownDlls `.text` unhooking:** [[known-dll-unhook]] (ORCx41; iterates loaded DLLs; maps trusted copies from `\KnownDlls`; replaces hooked `.text` sections and restores protections; native syscalls for memory/map ops; EDR/anti-cheat hook evasion research) (source: wiki/sources/descriptions/ORCx41__KnownDllUnhook.md) - **User-mode PE instrumentation:** early-stage toolkit [[pevisor]] (Nitr0-G; C/C++; PeVisor component; Blackbone process control/hooking/mapping + Unicorn emulation; protection vs unprotection test material; PE internals and runtime hook research for malware/game-security analysts; README [PE]) (source: wiki/sources/descriptions/Nitr0-G__PeVisor.md) - **PEB-less module base resolution:** Rust library/CLI [[moonwalk]] (Teach2Breach; stack-walk from TEB/stack bounds to find loaded DLL bases without PEB LDR list walk; VirtualQuery or API-free stealth variants; CLI + library; offensive security / low-level tooling where traditional module enumeration may be monitored) (source: wiki/sources/descriptions/Teach2Breach__moonwalk.md) - **Ring3 DLL load notifications:** `LdrRegisterDllNotification` callback research/modding samples such as [[dllnotif]] (blaquee; C++/C++; anti-cheat engineers / defensive researchers; Windows Ring3 callback lane) (source: wiki/sources/descriptions/blaquee__dllnotif.md); complements in-debugger inspection via [[x64dbg-view-dll-notification]]. - **Structures:** EPROCESS/ETHREAD, MMVAD, DRIVER_OBJECT, IRP; SSDT/IDT; ARK-style kernel hook/injection demo collections such as [[ark-tools]] (ChengChengCC; C/C++ Visual Studio projects; debug-register hooks, IDT/GDT hooks, kernel APC injection, shadow SSDT inline hooking, registry driver ops, WOW64 cross-arch injection; rootkit technique / defensive detection study; Some kernel research) (source: wiki/sources/descriptions/ChengChengCC__Ark-tools.md); PspCidTable; PiDDBCacheTable / MmUnloadedDrivers / PoolBigPageTable; local APIC register R/W and IPI delivery research such as [[apic]] (xAPIC / x2APIC; C++ / KM driver; timing/detection experiments) (source: wiki/sources/descriptions/noahware__apic.md); Intel **RAPL** package/DRAM energy metrics via kernel drivers such as [[windows-rapl-driver]] (WindowsKernelModeDriver10.0; bare-metal hosts; Detection:HWID research) (source: wiki/sources/descriptions/hubblo-org__windows-rapl-driver.md); WinRing0 per-core temperature sample such as [[winring0]] (ashleyhung; C++ console; bundled WinRing0 driver/API → CPUID + MSR temps; admin; hardware monitoring / low-level systems programming practice) (source: wiki/sources/descriptions/ashleyhung__WinRing0.md); VAD tree abuse / executable-page concealment injectors such as [[kernel-vad-injector]] (gmh5225; unsigned-driver manual map; `MiAllocateVad`/`MiInsertVad`/`MiInsertVadCharges` pattern-find; allocate+remove VAD post-map; PatchGuard-safe `xKdEnumerateDebuggingDevices` hook comms; Hide VAD) (source: wiki/sources/descriptions/gmh5225__Kernel-VAD-Injector.md); educational process VAD enumeration PoCs such as [[wkpe]] (am0nsec; WDK-style driver experiments + user-mode companions; MM/VAD tree listing; build/symbol coupling; Enumerate VAD) (source: wiki/sources/descriptions/am0nsec__wkpe.md); ACE-Guard client toolkit [[sguard-limit]] (H3d9; UM C++ controller + kernel C/asm; virtual memory ops, VAD traversal, suspend/resume, detour hooks; Visual Studio; anti-cheat RE / bypass experimentation) (source: wiki/sources/descriptions/H3d9__sguard_limit.md); extend-map DLL injectors such as [[modmap]] (btbd; `MiAllocateVad` post-module alloc + LDR entry size extension; payload appears as part of host module; module-enumeration evasion research) complement that VAD/LDR lane. (source: wiki/sources/descriptions/btbd__modmap.md) Driver-assisted memory/map frameworks such as [[memmap]] (KGB-1337; C++; request-based comms for cross-process R/W, allocation, protection changes, module queries; extend-map + API-call-path execution samples; Extend Manual Map) complement that lane. (source: wiki/sources/descriptions/KGB-1337__memmap.md) C++ mapped-kernel-driver injector frameworks such as [[face-injector-v2]] (KANKOSHEV; payload dropper + privilege elevation + randomized staging paths + mapper execution flow; multiple game targets; explicit ban warnings; Injection/Testing; educational driver-backed injection study) complement that lane. (source: wiki/sources/descriptions/KANKOSHEV__face-injector-v2.md); kernel hook-command manual-map injectors for EAC/BE research such as [[kernel-eac-be-injector]] (JGonz1337; kernel memory alloc/exposure + pointer-swap hooks; user-mode reloc/import/section write + remote DllMain + cleanup; PTE.User) complement that lane. (source: wiki/sources/descriptions/JGonz1337__kernel-eac-be-injector.md); stealthy KM manual-map injectors such as [[stealthy-kernelmode-injector]] (charliewolfe; C driver; APC/thread-hijack/image-load-callback paths; PEB module-list + allocation-metadata cleanup; PTE/VAD Manual Map; cheat / injection:windows) (source: wiki/sources/descriptions/charliewolfe__Stealthy-Kernelmode-Injector.md); NX-bit swap + VAD-hide kernel DLL injectors such as [[mminject]] (SDXT; C; writable alloc + page-table NX swap for execute; VAD manipulation; dynamic kernel data / I/O / loader; cheat / Using NX Bit Swapping and VAD hide) (source: wiki/sources/descriptions/SDXT__MMInject.md); defensive pointer-integrity PoC [[pointer-guard]] (charliewolfe; C/C++; HWBP or PAGE_GUARD on function pointers / vtable entries; Anti Cheat research) (source: wiki/sources/descriptions/charliewolfe__PointerGuard.md) - **KMDF framework RE:** IDA Pro plugin [[ida-kmdf]] annotates WDF structures, callback registrations, I/O queues, and device-init patterns in KMDF driver binaries (type defs + named framework calls). (source: wiki/sources/descriptions/thalium__ida_kmdf.md) General Windows kernel driver RE via [[driver-buddy-reloaded]] (IDA Pro plugin; IOCTL dispatch, IRP handlers, vulnerable-driver pattern ID, common WDM structure annotations; gmh5225; Windows Kernel Analysis) complements WDF-specific annotation. (source: wiki/sources/descriptions/gmh5225__DriverBuddyReloaded.md) Cursor RVA clipboard copy via [[copy-rva]] (RomanRybachek; Python IDAPython; context menu; WinDbg breakpoints on unsymbolized `.sys` files) bridges static IDA driver IDBs to live kernel attach. (source: wiki/sources/descriptions/RomanRybachek__Copy_RVA.md) Bitfield flag visualization in disassembly via [[ida-bitfields]] (register/structure bit flags; IOCTL and driver state-machine RE; Windows Kernel Enhance) complements WDF annotation for flag-heavy kernel code. (source: wiki/sources/descriptions/gmh5225__ida_bitfields.md) Hex-Rays NT kernel type enrichment via [[ntrays]] (NTSTATUS codes, IOCTL definitions, kernel object types, EPROCESS/ETHREAD field accesses; ntoskrnl and driver RE; Windows Kernel Enhance) improves decompiler output alongside WDF and bitfield plugins. (source: wiki/sources/descriptions/gmh5225__NtRays.md) Go static driver analysis via [[cognitor]] (IDA/Ghidra export ingest; IOCTL handlers, access-check gaps, ALPC/COM issues, unsafe native API patterns; configurable rules; Patch Tuesday PE/driver semantic diff, SARIF/MD/JSON dossiers) complements interactive KMDF annotation for defensive driver review. (source: wiki/sources/descriptions/kernelstub__Cognitor.md) In-IDA vulnerability triage via [[driver-vuln-analyzer-ida-plugin]] (CyberSecurityUP; Python IDAPython; auto-extract/decode IOCTL `CTL_CODE` fields, flag `METHOD_NEITHER` and sensitive kernel API usage; consolidated JSON export; driver attack-surface assessment) complements both lanes for offensive static review. (source: wiki/sources/descriptions/CyberSecurityUP__DriverVuln-Analyzer-IDA-Plugin.md) Pipeline-scale automated driver vulnerability research via [[deepzero]] (416rehman; parse/decompile Windows kernel drivers at scale; AI-agent analysis of exploitable IOCTLs; BYOVD/LOLDriver attack-surface study) extends that lane beyond interactive IDA plugins. (source: wiki/sources/descriptions/416rehman__DeepZero.md) Standalone driver static analysis and bug hunting via [[drveye]] (0xDbgMan; IOCTL dispatch recovery, taint analysis, emulation-based handler tracing, certificate verification, YARA scanning, PoC generation; discover IOCTLs, symbolic links, and certificate checks; exploitation triage for kernel drivers) complements pipeline and in-IDA lanes. (source: wiki/sources/descriptions/0xDbgMan__DrvEye.md) - **Syscall tables:** versioned **win32k.sys** binary corpora such as [[win32k-file-collection]] (gmh5225; multi-build **win32k.sys** and related GUI-subsystem binaries for patch diffing and win32k attack-surface research) and [[win32k-file-collection2]] (Win10/11 build snapshots for offline diff of GUI-subsystem syscalls and input-path internals—not turnkey analyzers) complement PDB-backed SSN extraction in the same lane; call-path mapping notebooks such as [[driver-communication-list]] (gmh5225; documented user→kernel transitions—e.g. `win32u.dll` through `win32k.sys`/`win32base.sys` to `dxgkrnl.sys`; tracing breadcrumbs for debugger/disassembler follow-up—not a turnkey analyzer) (source: wiki/sources/descriptions/gmh5225__Driver-Communication-List.md) (source: wiki/sources/descriptions/gmh5225__win32k_file_collection.md) (source: wiki/sources/descriptions/gmh5225__win32k_file_collection2.md); win32k **NtUserHardErrorControl** kernel exploit PoCs such as [[angryorchard]] (gmh5225; elevate calling thread to KernelMode → arbitrary kernel R/W; Some Tricks / win32k attack surface) (source: wiki/sources/descriptions/gmh5225__ANGRYORCHARD.md) win32k **TAGWND** DKOM overlay-hiding PoCs such as [[kernel-overlay-hider]] (J0xna; kernel driver locates and patches win32k window structures to hide overlay HWNDs from enumeration; user-mode DirectX overlay test harness; low-level GUI-subsystem internals / overlay visibility research) sit beside win32k corpora in the same GUI-subsystem lane. (source: wiki/sources/descriptions/J0xna__Kernel-Overlay-Hider.md) Session-space win32k dispatch hooking via [[win32khooker]] (GetRektBoy724; C++ kernel driver; process attach + syscall mapping + runtime disassembly to resolve hook targets when pointers live in opaque session-state instead of global `.data`; `.data` ptr swapper for newer win32k; GUI-subsystem / AC / defensive RE research) extends that lane. (source: wiki/sources/descriptions/GetRektBoy724__Win32kHooker.md) Win32k user-mode callback references such as those in [[eft]] (Splitx12; `usercallback.h` documents **`KeUserModeCallBack`** on Win10 for GUI-subsystem callback research in internal cheat stacks; cheat / game:eft) and dedicated kernel demos such as [[keusermodecallback]] (ExpLife0011; IOCTL driver; PEB/module export walk to resolve user32/MessageBoxA; 32/64-bit callback argument stubs; kernel-to-user transition / callback execution primitive research; README `[KeUserModeCallBack]`) (source: wiki/sources/descriptions/ExpLife0011__KeUserModeCallBack.md) and kernel APC + `KeUserModeCallback` remote execution PoCs such as [[remote-call]] (1401199262; C++; arbitrary-target user-mode code without RWX shellcode allocation in target; driver I/O pivot + controlled context restoration; advanced process injection + AC detection trade-off research; README `[APC Remote Call]`) (source: wiki/sources/descriptions/1401199262__RemoteCall.md) sit beside win32k syscall corpora in the same GUI-subsystem lane. (source: wiki/sources/descriptions/Splitx12__eft.md) SSDT-hooking debugger-hide drivers such as [[titanhide]] (Nt* return tampering for per-process anti-debug bypass; cheat / debugging) sit beside defensive SSDT inspection in tools such as [[openark]] (source: wiki/sources/descriptions/mrexodia__TitanHide.md), C++ anti-rootkit platform [[winark]] (BeneficialCode; drivers, symbol/PE parsers, monitoring modules, investigation UI; modern Windows; rootkit hunting and anti-cheat internals analysis; Tool) (source: wiki/sources/descriptions/BeneficialCode__WinArk.md), and console scanning suite [[slauc91-anticheat]] (SLAUC91; Native WinAPI process inspection + SSDT/IDT/IRP/MSR hook checks; game-security rootkit/cheat scanner prototype) (source: wiki/sources/descriptions/SLAUC91__AntiCheat.md); pre-generated multi-service NT syscall reference tables such as [[syscall-tables]] (hfiref0x; ntoskrnl/win32k/IUM SSN maps NT5.2→Win11 x64/ARM64; Zydis extraction from ntdll/win32u; scg + sstComposer; online HTML views) complement per-build PDB extraction via [[ntsleuth]] (JSON / C header dumps for direct-syscall research). (source: wiki/sources/descriptions/hfiref0x__SyscallTables.md) (source: wiki/sources/descriptions/xaitax__NTSleuth.md) NT x64 syscall fuzzer [[ntcall64]] (hfiref0x; C + minimal asm; stress-tests ntoskrnl and optional win32k Shadow SSDT on Win7+; randomized parameters with optional heuristics; INI blacklist, per-ID targeting, configurable pass counts, file/serial logging; LocalSystem elevation; kernel stability/vulnerability research; reported win32k/ntoskrnl handler flaws) extends the same service-table lane. (source: wiki/sources/descriptions/hfiref0x__NtCall64.md) Modular C++20 header-only direct-syscall invocation such as [[syscalls-cpp]] sits in the same Compile Time / AC research lane. (source: wiki/sources/descriptions/sapdragon__syscalls-cpp.md) Header-only C++ inline direct-syscall generation such as [[inline-syscall]] (JustasMasiulis; macro wrappers; compact inlinable x64 machine code; avoids normal import-table usage; anti-hooking / low-level systems programming) and simple C++ direct-syscall wrappers with x86/x64 support (gmh5225) sit in the same invocation lane. (source: wiki/sources/descriptions/JustasMasiulis__inline_syscall.md) (source: wiki/sources/descriptions/gmh5225__inline-syscall.md) Header-only C++20 **ARM64 Windows** direct-syscall library [[armcall]] (noahware; ntdll export parse + SVC immediate extraction; dynamic executable stubs bypass hooked import thunks; AC_SYSCALL macros; WoA anti-hooking / low-level RE) extends that invocation lane. (source: wiki/sources/descriptions/noahware__armcall.md) Indirect syscall samples with runtime SSN/syscall-instruction resolve and `ntdll` return-address spoof such as [[doom-syscalls]] (SilentisVox; userland hook / RIP-return evasion research) extend that lane. (source: wiki/sources/descriptions/SilentisVox__DoomSyscalls.md) Header-only C++ direct/indirect syscall library [[ebyte-syscalls]] (EvilBytecode; PEB loader walk + ntdll export parse for runtime SSN resolve; indirect syscall trampolines for EDR/AC hook evasion; optional VEH guard-page/INT3 call obfuscation without RWX stub allocation; syscall hook bypass / detection research) (source: wiki/sources/descriptions/EvilBytecode__Ebyte-Syscalls.md) Kernel-mode lazy import hiding via [[kli]] — header-only lazy_importer alternative for KM driver development (Some Tricks / Windows Ring0 / Lazy Importer). (source: wiki/sources/descriptions/hypervisor__kli.md) Extended [[kli-ex]] fork adds random seeds, resolve caching, hidden globals, and customizable encryption over the same `KLI_CALL` API. (source: wiki/sources/descriptions/gmh5225__kli-ex.md) Direct syscall helpers such as [[higu-ntcall]] (jnastarot; Some Tricks / Windows Ring3; partial ENUM support with parameter-conversion caveats; Windows/Linux/mobile) sit in the same invocation lane. (source: wiki/sources/descriptions/jnastarot__HIGU_ntcall.md) General Windows PDB read/merge/analyze via [[pdb]] (C++ DIA SDK; old formats + `pdb.cfg`) supports the same symbol-resolution lane for kernel/usermode debug databases. (source: wiki/sources/descriptions/sonyps5201314__pdb.md) GUI MSDIA symbol/property browsing via [[diasymbolview]] (Delphi; navigable PDB hierarchy; 200+ symbol properties; register-name resolution) aids manual inspection of kernel/driver PDB metadata before debugger import. (source: wiki/sources/descriptions/diversenok__DiaSymbolView.md) Standalone PDB stream parsing via [[pdbr]] (Python + Rich; function/type/global/source extraction without DIA SDK) complements headless symbol triage before dbghelp import. (source: wiki/sources/descriptions/cansarigol__pdbr.md) Native Rust PDB read/write via [[pdb-rs]] (MSF/CodeView DBI/TPI/IPI; symbol/type encode-decode; x86/AMD64/ARM64) offers a cross-platform programmatic alternative in the same lane. (source: wiki/sources/descriptions/microsoft__pdb-rs.md) In-driver PDB parsing for Ring0 symbol work via [[kpdb]] (GetRektBoy724 pure C with symbol+type streams; rbmm C++; runtime parse avoids brittle offsets/sig scans; Some Tricks / Windows Ring0). (source: wiki/sources/descriptions/GetRektBoy724__KPDB.md) (source: wiki/sources/descriptions/rbmm__KPDB.md) Runtime Ring3 inspection via Instrumentation Callback (fires on every kernel-syscall return) is covered by samples such as [[instrumentation-callback-syscall-logger]]. (source: wiki/sources/descriptions/x86matthew__InstrumentationCallbackSyscallLogger.md) [[instrumentation-callbacks]] (Deputation; C++/asm; TLS recursion mitigation; syscall + exception interception; telemetry/runtime-control research; Instrumentation Callback) extends that lane. (source: wiki/sources/descriptions/Deputation__instrumentation_callbacks.md) [[instrumentation-callbacks-lib]] (1027565; C++/asm user-mode library PoC; syscall/APC/exception/user-mode-callback/thread-init kernel→user transitions; NTDLL-only deps; x64; Windows internals + EDR telemetry research; Instrumentation Callback) broadens that lane. (source: wiki/sources/descriptions/1027565__InstrumentationCallbacks.md) Hooking PoCs such as [[hooking-via-instrumentation-callback]] use `ProcessInstrumentationCallback` to inspect/modify syscall results without ntdll stub patches. (source: wiki/sources/descriptions/secrary__Hooking-via-InstrumentationCallback.md) [[nasty-alignment]] demonstrates alignment-check edge cases that raise `STATUS_DATATYPE_MISALIGNMENT` inside Instrumentation Callback handlers. (source: wiki/sources/descriptions/asamy__NastyAlignment.md) Related ETW TI / syscall-hook samples such as [[etwti-syscall-hook]] extend the same Instrumentation Callback research surface. (source: wiki/sources/descriptions/paranoidninja__EtwTi-Syscall-Hook.md) Kaspersky hypervisor syscall redirection such as [[kaspersky-hook]] (gmh5225; load `klhk.sys` + custom driver; hijack **`IA32_LSTAR`** dispatch table to subvert the kernel syscall handler; README `[Kaspersky]`) illustrates third-party AV hypervisor abuse of the syscall entry path. (source: wiki/sources/descriptions/gmh5225__KasperskyHook.md) Kaspersky signed-driver privilege abuse such as [[evil-kaspersky]] (gmh5225; abuse Kaspersky signed kernel-mode drivers for unauthorized privileged operations; kernel code execution while masquerading as legitimate AV activity; README `[Kaspersky]`) complements hypervisor syscall redirection in [[kaspersky-hook]]. (source: wiki/sources/descriptions/gmh5225__EvilKaspersky.md) Avast hypervisor-component abuse such as [[avasthv]] (gmh5225; signed Avast hypervisor driver → kernel-level ops; elevated privileges or hypervisor-context code execution; DSE and anti-cheat bypass via trusted AV driver status; README `[Avast]`) extends the same AV hypervisor BYOVD lane. (source: wiki/sources/descriptions/gmh5225__AvastHV.md) Title-specific monitors of hidden syscalls from Call of Duty anticheat such as [[hidden-syscall-monitoring]] sit in the same syscall-telemetry RE lane. (source: wiki/sources/descriptions/ssnob__hidden_syscall_monitoring.md) Defensive direct/indirect syscall origin validation such as [[syscall-detect]] (C; Instrumentation Callback or thread stack inspection; custom stub vs ntdll) demonstrates AC/EDR heuristics for hooking evasion. (source: wiki/sources/descriptions/jackullrich__syscall-detect.md) Rust no_std hash-based WinAPI resolution such as [[rs-ldr]] (alfarom256; PEB module walk + export parse incl. forwards; LdrLoadDll via DynApi; compile-time XOR strings; optional Hell's Gate-style SSN resolver; NODEFAULTLIB; stealth API resolution) (source: wiki/sources/descriptions/alfarom256__rs-ldr.md) Educational Windows AC PoCs tagged Instrumentation Callback such as [[anticheat-poc]] (debugger / integrity / signature-scan / process enum) sit in the same lane. (source: wiki/sources/descriptions/thetuh__anticheat-poc.md) Driver-backed AC **TestBench** research such as [[anti-cheat-testbench]] (ekknod; C++/C; anti-cheat research + driver development + hooking; Open Source Anti Cheat System) extends that PoC lane for kernel-level AC evaluation. (source: wiki/sources/descriptions/ekknod__Anti-Cheat-TestBench.md) C++/CLI user-mode anti-tamper via undocumented NT APIs and runtime modifications such as [[umium]] (detect/neutralize debug, memory tamper, sandbox; Anti Cheat → Anti Debugging) sits in the same Ring3 NT research lane. (source: wiki/sources/descriptions/hotline1337__umium.md) Kernel AC PoCs such as [[darken-anticheat]] (KM driver communication / integrity / module verify / signature scan / debugger / overlay) sit in the same AC–driver research lane. (source: wiki/sources/descriptions/noahware__darken-anticheat.md) gmh5225 reference implementation [[anti-cheat-chrysalis]] / [[anticheat]] (process integrity, module scan, memory pattern detection, debugger detection, overlay monitoring, driver comm; Anti Cheat / guide; Open Source Anti Cheat System) extends that lane. (source: wiki/sources/descriptions/gmh5225__AntiCheat-chrysalis.md) (source: wiki/sources/descriptions/gmh5225__AntiCheat.md) Broader unconventional Ring3 PoCs (memory analysis / asset pipelines) appear in collections such as [[function-collections]]. (source: wiki/sources/descriptions/whokilleddb__function-collections.md) - **WinDbg automation:** JS WinDbg scripts such as [[windbg-scripts]] for kernel-level debug/modding workflows (Cheat → WinDbg Plugins). (source: wiki/sources/descriptions/yardenshafir__WinDbg_Scripts.md) KasperskyLab dump-triage JS scripts [[windbg-js-scripts]] (exception-record candidates, STL map walk, broken noexcept stack-trace repair, x86 stacks in x64 kernel dumps; manifest XML + Python helper; anti-cheat/malware dump analysis; Cheat → JS Scripts) (source: wiki/sources/descriptions/KasperskyLab__WinDbg-JS-Scripts.md) Practical script/query cookbook [[windbg-cookbook]] (TimMisiak; JS data-model automation; dependency inspection, stack collection/corruption detection, TTD analysis; ready-to-run `dx` examples; WinDbg) (source: wiki/sources/descriptions/TimMisiak__WinDbgCookbook.md) WinDbg command extension [[swishdbgext]] (comaeio; Matt Suiche; expands commands and fixes/improves built-ins; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/comaeio__SwishDbgExt.md) pykd PEDA-like UI extension [[twindbg]] (bruce30262; register/disasm/stack smart-deref on step/trace; PEDA-style memory/symbol commands; exploit dev + binary analysis; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/bruce30262__TWindbg.md) curated WinDbg extension catalog [[awesome-windbg-extensions]] (anhkgg; kernel analysis, incident response, rootkit hunting, memory inspection, debugger automation; Cheat → WinDbg reference index) (source: wiki/sources/descriptions/anhkgg__awesome-windbg-extensions.md) Remote kernel debugging setup/reference guides such as [[windows-kernel-debugging-guide]] (documentation; cheat / guide lane) complement live attach workflows. (source: wiki/sources/descriptions/konstantin89__windows-kernel-debugging-guide.md) IDA Pro + VMware GDB live kernel debugging via [[ida-vmware-windows-gdb]] (IDA GDB debugger wired to VMware guest Windows kernel stub; breakpoints/memory/step; cheat / guide) (source: wiki/sources/descriptions/gmh5225__ida_vmware_windows_gdb.md) VirtualKD-Redux VM kernel debug acceleration via [[virtualkd-redux]] (4d61726b; C/C++ driver + host-side components; VMware/VirtualBox; legacy Windows through Win11; current WinDbg; modern VS build workflow; faster VM kernel debug for systems security research) (source: wiki/sources/descriptions/4d61726b__VirtualKD-Redux.md) IDA Pro + Bochs emulation kernel debugging via [[ida-bochs-windows]] (Bochs software CPU backend on Windows; full-system stepping including kernel-mode code; cheat / guide) (source: wiki/sources/descriptions/gmh5225__ida_bochs_windows.md) Linux-host KVM/QEMU WinDbg-style kernel debugger via [[ntoseye]] (dmaivel; Win10/11 guest; GDB stub to hypervisor for memory/registers; WinDbg-like commands, PDB fetch/parse, breakpoints; Kernel Debugger; no Windows host/WinDbg required) (source: wiki/sources/descriptions/dmaivel__ntoseye.md) COM tracing via [[comon]] (WinDbg extension; class creation + interface querying; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/lowleveldesign__comon.md) Token/heap pointer visualization via [[dk]] (refactored tokenext; SVG overlays for local buffers, symbols, heap allocs + clickable allocation history; Cheat → WinDbg Plugins) (source: wiki/sources/descriptions/long123king__dk.md) Intel LBR/BTS branch-trace collection via kernel drivers such as [[branch-monitoring-project]] (PMI; branch-level execution monitoring without `.text` patches; malware/integrity RE) and Intel hardware-trace libraries such as [[libiht]] (Tencent Xuanwu Lab; Intel Hardware Trace Library; cheat / Windows kernel explorer) sit beside ETW/PMI/NMI handler research; Windows IPT capture stacks such as [[winipt]] (`ipt.sys` wrapper; per-process/per-CPU trace collection), Rust `ipt.sys` library [[libipt-rs]] (user-mode DeviceIoControl; start/stop/retrieve traces; RE-derived driver interface; no parsing) (source: wiki/sources/descriptions/australeo__libipt-rs.md), and [[windows-intel-pt]] (own KM driver configuring IPT MSRs + trace buffers; user-mode start/stop API; per-process and system-wide modes; coverage / fuzzing / execution tracing) extend the same hardware-trace lane; [[processor-trace]] (libipt; Intel reference PT packet/instruction decoder) is the usual downstream decode step for captured IPT buffers; [[pt-detector]] (DProvinciani; Windows research prototype; KM+UM PT packet capture + execution-stream decode for ROP/JOP-style suspicious control flow; C/C++ + Python; exploit detection / CFI experimentation; README [Intel PT]) (source: wiki/sources/descriptions/DProvinciani__pt-detector.md) applies that decode lane to code-reuse exploit detection research; [[ingsoc]] (CristiNacu; Windows Intel PT toolkit; KM driver configures IPT collection; user-mode controller + Python decoder; Kafka packet streaming; execution reconstruction + trace timing/control-flow analytics; exploit/malware + code-reuse behavior research; README [Intel PT]) (source: wiki/sources/descriptions/CristiNacu__ingsoc.md) extends that toolkit lane with stream analytics; [[intel-pcm]] (Intel Performance Counter Monitor; CPU/memory/PCIe/power counters; Docker/CXL) offers official PMU telemetry beside that lane; [[pmctrace]] (C; real-time PMC collection via ETW; cache/branch/instruction counters; profiling / side-channel RE) provides low-level register access in the same PMU lane; [[pmi-hpc]] (PMI + HPC; interrupt on branch misprediction / cache miss; anomalous execution / code injection / ROP detection research) demonstrates security-monitoring use of PMI-driven counter events beside passive PMC profiling; [[perfmon]] (KelvinMsft; kernel research driver; PMU/PMI flows, APIC handling, interrupt paths; SSDT monitoring + hook-style interception; reference papers + test program; Win10-era hardware-assisted monitoring; README PMI Callback) (source: wiki/sources/descriptions/KelvinMsft__PerfMon.md) explores foundational PMU control/observation beside detection- and offensive-PMI samples; [[thread-spy]] (KelvinMsft; hardware-assisted thread hijack via PMI callback; take over running threads without instruction-byte patches; stealth execution redirection / code injection in target context; anti-cheat bypass research; README PMI Callback) demonstrates offensive PMI use for in-process execution redirection beside detection-oriented HPC work; [[driver-intel-pebs-loophpcs]] (gmh5225; LoopHPCs filter-driver; PEBS + LBR loop hot-loop telemetry; unpacking-oriented malware RE; README `[Intel PEBs]`) extends that lane toward tight-loop runtime profiling; [[pdf-pmc-x86]] (PDF study on x86 PMC/PMI; documentation archive for counter-based monitoring, telemetry, and Windows security research) provides background reference material in the same PMU lane. (source: wiki/sources/descriptions/marcusbotacin__BranchMonitoringProject.md) (source: wiki/sources/descriptions/gmh5225__pmctrace.md) (source: wiki/sources/descriptions/gmh5225__PMI-hpc.md) (source: wiki/sources/descriptions/KelvinMsft__ThreadSpy.md) (source: wiki/sources/descriptions/gmh5225__Driver-intel-PEBs-LoopHPCs.md) (source: wiki/sources/descriptions/gmh5225__PDF-PMC-X86.md) (source: wiki/sources/descriptions/libiht__libiht.md) (source: wiki/sources/descriptions/intelpt__winipt.md) (source: wiki/sources/descriptions/intelpt__processor-trace.md) (source: wiki/sources/descriptions/intelpt__WindowsIntelPT.md) (source: wiki/sources/descriptions/intel__pcm.md) AMD Instruction-Based Sampling tooling such as [[amd-ibs-toolkit]] (hardware instruction subset sampling; cheat / Windows kernel explorer / AMD Sampling) extends that hardware-trace lane on AMD hosts. (source: wiki/sources/descriptions/jlgreathouse__AMD_IBS_Toolkit.md) Kernel driver dynamic-script prototyping via [[ntphp]] (PHP runtime inside WDK `.sys` modules; Anti Cheat → Dynamic Script) offers an alternate rapid-iteration lane beside static C rebuilds. (source: wiki/sources/descriptions/mrexodia__NtPhp.md) Lua 5.4 kernel-scripting PoC such as [[ntlua]] (can1357; Lua interpreter embedded in WDK driver; user-mode client sends scripts for ring-0 evaluation; phys/virt memory, process enum, MSR R/W; kernel introspection / exploit-dev research) extends the same dynamic-script lane beside [[pawnio]] (source: wiki/sources/descriptions/can1357__NtLua.md). Register-machine bytecode interpreter such as [[gexec]] (zer0condition; embeddable C VM without JIT; gasm assembler + gvmlift x86-64 PE lifter; fixed 16-byte instructions ~180 opcodes; host callbacks for kernel memory/MSR/physical access; updatable portable driver logic; kernel security / AC development research) extends that lane with verified bytecode modules. (source: wiki/sources/descriptions/zer0condition__gexec.md) Signed WDM driver platforms such as [[goodmans-kernel]] (zer0condition; wasm3 hot-loads unsigned wasm32 kernel modules via IOCTL with NT/HAL FFI, per-module permission manifests, InfinityHook trampolines, process/image notify callbacks; HVCI-compliant hooking / tracing / introspection) extend the same updatable-logic lane with WebAssembly instead of custom bytecode. (source: wiki/sources/descriptions/zer0condition__GoodmansKernel.md) Agent-facing CDB/WinDbg MCP via [[mcp-windbg]] (Python; crash-dump triage + remote debug sessions) sits in the same WinDbg Plugins / MCP lane. (source: wiki/sources/descriptions/svnscha__mcp-windbg.md) Windows CLI + MCP [[windbg-tool]] (Devolutions; Rust + TTD Replay API bridge; `.run` trace replay, register/memory/disasm/symbol triage, user/kernel crash dumps; JSON commands + MCP for AI agents; live probes, replay daemon, WinDbg install/update helpers) (source: wiki/sources/descriptions/Devolutions__windbg-tool.md); Windows process-tree memory profiler [[onlooker]] (DenuvoSoftwareSolutions; C++/CMake/Qt; records process-tree memory stats like Linux time; Qt GUI trace inspector + JSON conversion; memory growth/OOM/performance regression diagnosis in native toolchains) (source: wiki/sources/descriptions/DenuvoSoftwareSolutions__Onlooker.md) Kernel memory structure reversing environment [[kreclassex]] (BeneficialCode; C++; WinDbg extension + GUI; connect to debug session, inspect kernel memory layouts, resolve function pointers, generate reconstructed type views; anti-cheat kernel RE) (source: wiki/sources/descriptions/BeneficialCode__KReClassEx.md) Agentic WinDbg copilot [[windbg-copilot]] (0xeb; C++ extension; AI Q&A, auto command execution with explanations, multi-provider models, persistent context, decompilation help, HTTP/MCP + CLI; crash triage, exploit debugging, Windows security analysis) (source: wiki/sources/descriptions/0xeb__windbg-copilot.md) WinDbg x64 LLM decompiler extension via [[windbg-decompile-ext]] (live function disasm → verified pseudocode; Cheat → WinDbg Plugins) adds in-debugger pseudocode generation during live attach. (source: wiki/sources/descriptions/kernullist__windbg-decompile-ext.md) WinDbg callback enumeration extension [[windbg-extensions]] (ch3rn0byl; walks `PspCreateProcessNotifyRoutine` / `PspCreateThreadNotifyRoutine` / `PspLoadImageNotifyRoutine`; filter process/thread/image/all; AC / rootkit / driver analysis during live KD) (source: wiki/sources/descriptions/ch3rn0byl__WinDbg-Extensions.md) LiveKD-style interactive kernel debugging via [[kn-live-dbg]] (kernel driver for memory inspection, module enumeration, Zydis disassembly; user-mode TUI for symbols/types; no traditional KD setup) (source: wiki/sources/descriptions/kernullist__kn-live-dbg.md) Driver-backed kernel debugging toolkit [[kdbg]] (kernel driver + CLI; user/kernel memory R/W, module/thread enumeration, trace features; x64; driver load may alter signing policy; cheat / Tool) (source: wiki/sources/descriptions/allogic__KDBG.md) Stealth kernel-debugger protocol via [[nokd]] (copies/decodes `KdDebuggerDataBlock` locally without setting ntoskrnl KD globals; feeds WinDbg; hard to flag for `KdDebuggerEnabled`-style checks) (source: wiki/sources/descriptions/irql__nokd.md) Kernel-mode [[kdbgdecryptor]] sample decrypts KDBG via `KdDecodeBlockData` or manual `KiWaitNever`/`KiWaitAlways` copy-from-memory (stealthier decode path; kernel RE / AC memory-analysis study) (source: wiki/sources/descriptions/Air14__KDBGDecryptor.md) Anti-WinDbg-break PoC such as [[letme-gg]] (C++; gmh5225; prevent WinDbg kernel break/attach; Some Tricks / Windows Ring0 anti-debug research) (source: wiki/sources/descriptions/gmh5225__LetMeGG.md) Anti-kernel-debug detection driver PoC such as [[anti-kernel-debug-poc]] (C driver; gmh5225; debug port / `KdDebuggerEnabled` / `KUSER_SHARED_DATA` / interrupt checks vs WinDbg/KD; Some Tricks / Windows Ring0 anti-debug research) (source: wiki/sources/descriptions/gmh5225__AntiKernelDebug-POC.md) Experimental defensive anti-debug kernel driver [[majesty-technologies]] (Ahora57; C/C++ WDK driver; DKOM-style structure manipulation, instrumentation callback checks, hardware breakpoint checks, process/thread flag hardening, anti-hypervisor timing/anomaly checks; AC/protection research for kernel-level debugger resistance) (source: wiki/sources/descriptions/Ahora57__MAJESTY-technologies.md) Tutorial anti-anti-debug kernel drivers such as [[anti-anti-debugger-driver]] (AyinSama; C++ WDK driver; hooks native syscall paths for process/thread/handle/system-information queries; hook utilities + disassembly helpers redirect anti-debug probes; RE education / protected software analysis; README `[ETW Hook]`) (source: wiki/sources/descriptions/AyinSama__Anti-AntiDebuggerDriver.md). Windows ARM64 user-mode debugger [[koidbg]] (EN/PT docs; cheat / debugging lane for WoA RE) (source: wiki/sources/descriptions/keowu__koidbg.md) AI-assisted Windows security workbench [[kernforge]] (Go CLI/agent; project knowledge packs, investigate/simulate loops, source-level fuzz reasoning, verification plans, MCP skills, WDM/minifilter/registry-filter/WFP driver POC scaffolding; VS Code extension) targets kernel/AC codebase analysis and hardening rather than generic coding. (source: wiki/sources/descriptions/kernullist__kernforge.md) Autonomous Windows PoC development from patchwatch diffs via [[pocsmith]] (Claude agent + MCP Hyper-V/kd/Ghidra; write/build/verify on pre-patch VMs) extends that agent-MCP lane into iterative exploit construction. (source: wiki/sources/descriptions/originsec__pocsmith.md) IDA MCP with optional live kernel memory/module access via [[iida-mcp]] (`iida-mcp-ioctl` driver; static+dynamic RE for agents) bridges the same kernel-inspect / MCP lane from IDA. (source: wiki/sources/descriptions/saileaxh__iida-mcp.md) - **Cross-process kernel R/W:** MDL map + physical translate + CR3 page-table walk libraries such as [[ntmemory]] (research for kernel cheat memory paths / AC evasion). (source: wiki/sources/descriptions/zer0condition__NTMemory.md) Kernel-mode HWID spoof samples such as [[easy-hwid-spoofer]] (gmh5225; driver dispatch hooks + direct physical-memory patches for disk/NIC/GPU/SMBIOS serial IDs; cheat / HWID) apply that physical-translate lane to anti-cheat hardware fingerprints. (source: wiki/sources/descriptions/gmh5225__EASY-HWID-SPOOFER.md) Archival hook-minimal kernel HWID spoofer [[mutante]] (SamuelTulach; C/C++ WDK driver; disk serial / SMART / SMBIOS table fields; Visual Studio project; older-generation evasion reference; cheat / HWID) documents storage and firmware-table identifier manipulation without permanent hook dependencies. (source: wiki/sources/descriptions/SamuelTulach__mutante.md) Kernel-mode WMI static HWID spoofer PoC [[wmi-static-spoofer]] (Alex3434; memory + registry updates for WMI hardware serial paths; hook-minimal unload-after-apply design; configurable offsets + randomized serials; HWID evasion research; cheat / HWID) documents WMI-path identifier rewriting without persistent hooks. (source: wiki/sources/descriptions/Alex3434__wmi-static-spoofer.md) Defensive PCI/AHCI direct HWID collection PoCs such as [[pciban]] (KDIo3; brute-force PCI enumeration; storage-controller identifiers without conventional OS APIs; anti-cheat / Detection:HWID research; experimental) sit opposite those spoof samples in the same hardware-fingerprint lane. (source: wiki/sources/descriptions/KDIo3__PCIBan.md) Protected-process memory access framework [[meme-rw]] (SamuelTulach; C++/CMake PoC; vulnerable-driver mapping with driver-load helpers, process/module utilities, and memory R/W control; end-to-end target open + memory ops; anti-cheat bypass experimentation / defensive protected-memory research; cheat / kdmapper) (source: wiki/sources/descriptions/SamuelTulach__meme-rw.md) Kernel page-remapping PoC [[remap]] (EBalloon; C++; copies protected-process pages into another process address space; post-setup memory R/W and dump workflows; Windows 10 range caveats + cleanup crash warnings; anti-cheat bypass / process-memory research; cheat / Clone process) (source: wiki/sources/descriptions/EBalloon__Remap.md) Upstream BTBD [[hwid]] (original multi-surface IOCTL-hook spoofer + usermode registry/tracking cleanup; Win10 1507–1903; NVME IOCTL gap; cheat / HWID; btbd) is the baseline forked by [[driver-hwid-btbd-modified]]. (source: wiki/sources/descriptions/btbd__hwid.md) BTBD-style manually mapped storage-stack spoofers such as [[driver-hwid-btbd-modified]] (gmh5225; disk/partition IOCTL hooks; GPT/SMART / storahci RAID serial rewrite; Win1909 manual-map target; cheat / HWID) extend that lane with multi-surface disk-identity consistency. (source: wiki/sources/descriptions/gmh5225__Driver-HWID-btbd-modified.md) KMDF kernel HWID spoofer drivers such as [[hwid--spoofer]] (Theordernarkoz; C/KMDF; disk/mount/network control-path hooks; disk/NIC/SMBIOS/GPU identifier rewrite; anti-cheat evasion; cheat / HWID) extend that IOCTL-hook lane. (source: wiki/sources/descriptions/Theordernarkoz__Hwid--Spoofer.md) Minimal `MmCopyVirtualMemory` test drivers such as [[cheat-driver]] illustrate the simplest own-KM cross-process R/W path for AC stress-testing. (source: wiki/sources/descriptions/nkga__cheat-driver.md) Combined KM W/RPM + mouse_event samples such as [[norsefire]] (C++; cheat / RPM) sit in the same driver-backed memory + input lane. (source: wiki/sources/descriptions/nbqofficial__norsefire.md) DIRECT_IO IRP proxy driver PoCs such as [[usugumo]] (M3351AN; C/C++ + MASM; RPM/WPM, process/module lookup, mouse/keyboard injection, anti-capture + comm examples; explicit non-production PoC; kernel communication / game-security experimentation on x64 Windows; README Kernel-mode W/RPM/mouse_event for Windows) extend that lane. (source: wiki/sources/descriptions/M3351AN__Usugumo.md) Title-specific CS2 kernel-driver externals such as [[ukia-rpm]] (M3351AN; C++; kernel driver RPM + DirectX 9 ImGui overlay; aimbot/ESP/radar/recoil control; RPM-based external cheat + KM↔UM comm research; cheat / game:cs2 [External]) consume that cross-process KM R/W lane beside same-author PoCs. (source: wiki/sources/descriptions/M3351AN__UkiaRPM.md) Title-specific CS2 kernel-driver externals such as [[samidare]] (M3351AN; C++; FIFO-based kernel driver comm + DirectX overlay; offset management + game-data reads; driver-assisted external cheat + KM↔UM comm research; cheat / game:cs2 [External Ring3/Ring0]) extend that lane with FIFO-based driver I/O beside [[ukia-rpm]]. (source: wiki/sources/descriptions/M3351AN__Samidare.md) Stable kernel read/write driver samples such as [[readwrite-kernel-stable]] (C/C++; cheat / RPM; driver development / modding) sit in the same cross-process KM R/W lane. (source: wiki/sources/descriptions/juniorjacob__readwrite-kernel-stable.md) C++ IOCTL physical/virtual memory driver samples such as [[driver-physical-rw]] (Vekor64; DeviceIoControl request structs; read/write, alloc/protect, module-base lookup, process helpers; low-level security experimentation / cheat driver-comm study; Kernel-mode W/RPM for Windows) sit in the same standalone driver-primitives lane. (source: wiki/sources/descriptions/Vekor64__Driver-physical-rw.md) Kernel driver cheat frameworks such as [[ultra-driver-game-cheat]] (custom Windows driver; physical translate / MDL mapping; user-mode comm interface; AC handle-protection bypass study; Cheat Driver; gmh5225) sit in the same lane. (source: wiki/sources/descriptions/gmh5225__UltraDriver-Game-Cheat.md) DBVM-integrated cheat frameworks such as [[lilypublic]] (dot1991; kernel+user components; physical memory R/W, pattern scan, object callbacks, remote process manipulation; encrypted strings + compile-time obfuscation; cheat framework) extend that lane with hypervisor-assisted memory access beside [[anti-cheat-amateur]]. (source: wiki/sources/descriptions/dot1991__lilypublic.md) Modular KM+UM driver frameworks such as [[lithium-kernel]] (bootmgfw; C++/asm; custom IOCTL phys/virt R/W, DTB resolve, page-table walk, IDA-style pattern scan, cross-process alloc/protect, MouClass mouse callbacks, thread hide, NMI suppression, pool-tracker clean; low-level Windows RE / game-security research) sit in the same standalone driver-primitives lane. (source: wiki/sources/descriptions/bootmgfw__lithium-kernel.md) Title-specific Apex Legends externals such as [[apex-external-cheat]] (bootmgfw; Echo_Apex; kernel-driver comm + DX11 ImGui overlay; external RPM/ESP; cheat / game:apex legends [External]) consume KM↔UM primitives in an end-to-end cheat stack. (source: wiki/sources/descriptions/bootmgfw__apex-external-cheat.md) Simple CS:GO kernel cheats with hook-based KM↔UM communication such as [[kernel-csgo]] (C++; driver / modding; cheat / game:csgo) sit in the same hook-comm lane. (source: wiki/sources/descriptions/nbqofficial__kernel-csgo.md) CS:GO kernel driver + usermode IOCTL controller samples such as [[garhal-csgo]] (dretax; KM entity R/W; planned kernel DirectX overlay without UM injection; cheat / game:csgo) extend that lane. (source: wiki/sources/descriptions/dretax__GarHal_CSGO.md) Educational CS:GO kernel-driver PoCs with shared-memory KM↔UM comm such as [[smkernel-csgo]] (DeiVid-12; module-base lookup + process memory R/W; triggerbot sample; detectability tradeoffs vs kernel AC; cheat / game:csgo [Driver]) extend that lane. (source: wiki/sources/descriptions/DeiVid-12__SmKernel-CSGO.md) Full-kernel CS:GO external frameworks such as [[csgo-full-kernel]] (Sentient111; C++ KMDF; memory, draw, input, and game offsets entirely in Ring0—no conventional usermode cheat process; README Running from kernelmode) extend that lane. (source: wiki/sources/descriptions/Sentient111__Csgo-Full-kernel.md) Kernel-mode CS:GO cheat samples such as [[raybot-zero]] (R4YVEN; C++ Windows driver + minimal C# loader; triggerbot, bunnyhop, glow, kernel key-state reads; core logic without traditional usermode controller; game offsets + low-level memory routines; cheat development / kernel AC evasion research; README Kernel-mode) extend that lane. (source: wiki/sources/descriptions/R4YVEN__raybot-zero.md) Title-specific OOP cheat bases with kernel driver components such as [[simple-rust-base]] (Facepunch Rust; C/C++; rendering / modding; cheat / game:rust) extend that lane. (source: wiki/sources/descriptions/krispybyte__Simple-Rust-Base.md) [[simple-eft-base]] (Escape From Tarkov; C/C++; driver / rendering / animation; cheat / game:eft; stale offsets) follows the same OOP base pattern. (source: wiki/sources/descriptions/krispybyte__Simple-EFT-Base.md) External EFT cheat samples such as [[eft-external]] (frankie-11; C/C++; kernel-level work + overlays + modding; cheat / game:eft [External]) extend that lane as driver-backed externals. (source: wiki/sources/descriptions/frankie-11__eft-external.md) Streaming/external-display EFT cheat samples such as [[eft-streamed-cheat]] (fcancelog; driver-backed external Unity memory reads; separate-display radar/ESP; avoids in-process injection; cheat / game:eft [External/Streaming]) extend that lane as off-window streaming externals. (source: wiki/sources/descriptions/fcancelog__EftStreamedCheat.md) External EFT reversal frameworks such as [[pkernelinterface-eft]] (Nou4r; C++; kernel-assisted memory interaction + entity processing; ESP/aim modules; ImGui overlay; cheat / game:eft [External]) extend that lane as integrated external reversal scaffolds. (source: wiki/sources/descriptions/Nou4r__pKernelInterface-EFT.md) Title-specific COD Warzone external samples such as [[external-warzone-cheat]] (NMan1; C++; manually mapped kernel driver + usermode client; overlay hijack ESP; game SDK/offset scaffolding; cheat / game:cod warzone [External]) extend that lane as integrated Warzone external scaffolds beside [[warzone-internal]]. (source: wiki/sources/descriptions/NMan1__external-warzone-cheat.md) Title-specific Apex Legends kernel-driver external samples such as [[apex-legends-cheat]] (NMan1; C++; kernel driver + loader + client DLL; ESP / chams + input-assisted aim; syscall-hooking + kernel-thread execution bypass; kernel-mediated cheat pipeline RE; cheat / game:apex legends [External]) extend that lane beside [[apex-legends-driver-cheat]]. (source: wiki/sources/descriptions/NMan1__apex-legends-cheat.md) Hybrid Apex Legends UM+KM frameworks such as [[project-branthium]] (KaylinOwO; C++ Visual Studio; user-mode client + kernel driver; aimbot/ESP/entity cache/weapon prediction; ImGui + DirectX 9 overlay; low-level memory interaction in cheat and driver dirs; cheat / game:apex legends) document paired Ring0 memory access with in-process rendering under [[easy-anti-cheat]]. (source: wiki/sources/descriptions/KaylinOwO__Project-Branthium.md) Hybrid Apex Legends UM+KM frameworks such as [[uc-apex-remastered]] (BaconToaster; C++ Visual Studio/WDK; kernel driver privileged memory ops + communication routines; UM client gameplay modules; DirectX 9 + ImGui overlay; driver-assisted memory access research; cheat / game:apex legends) extend that paired Ring0 + overlay lane under [[easy-anti-cheat]]. (source: wiki/sources/descriptions/BaconToaster__UC-Apex-Remastered.md) Title-specific Rainbow Six Siege kernel-assisted external samples such as [[rainbow-six-cheat]] (NMan1; C/C++; kernel driver + external menu + shared-memory comm; ESP/chams + silent-aim/recoil/spread + unlock/movement mods; full-source kernel-assisted cheat framework RE; cheat / game:r6 [External]) extend that lane beside [[external-r6s-cheat]]. (source: wiki/sources/descriptions/NMan1__Rainbow-Six-Cheat.md) Title-specific Rainbow Six Siege v2 kernel-assisted external samples such as [[overflow-r6-v2]] (NMan1; C/C++; second-generation external framework; inline kernel function hook bypass + user-mode menu/rendering; combat/visual feature modules; kernel-assisted cheat architecture RE; cheat / game:r6 [External]) extend that lane as a v2 inline-hook sample beside [[rainbow-six-cheat]]. (source: wiki/sources/descriptions/NMan1__OverflowR6V2.md) Title-specific Rainbow Six Siege kernel-assisted internal samples such as [[internal-rainbow-six-cheat-v3]] (NMan1; C/C++; kernel injector + manually mapped user-mode DLL; D3D11 menu; ESP/aimbot/recoil/spread/movement/FOV; kernel-assisted injection + AC detection-surface RE; cheat / game:r6 [Internal]) complement the external [[rainbow-six-cheat]] / [[overflow-r6-v2]] lane from the same author. (source: wiki/sources/descriptions/NMan1__Internal-Rainbow-Six-Cheat-V3.md) Title-specific CrossFire kernel cheat samples such as [[titancf]] (C/C++; driver development / rendering / graphics; cheat / game:crossfire; gmh5225) extend that lane. (source: wiki/sources/descriptions/gmh5225__titancf.md) Title-specific MHXY (Fantasy Westward Journey / 梦幻西游) kernel modding samples such as [[mhxy]] (Python; driver development / modding; gmh5225) and [[mhxy-kernel]] (C/C++; kernel-level work and modding; cheat / game:mhxy; gmh5225) extend that lane. (source: wiki/sources/descriptions/gmh5225__mhxy.md) (source: wiki/sources/descriptions/gmh5225__mhxy_kernel.md) Title-specific Super People kernel cheat samples such as [[superpeople-client]] (C++; driver development / rendering / modding; cheat / game:super people; gmh5225) extend that lane. (source: wiki/sources/descriptions/gmh5225__superpeople-client.md) Title-specific Blood Hunt kernel cheat samples such as [[blood-hunt]] (C/C++; driver development / rendering / modding; cheat / game:bloodhunt; gmh5225) extend that lane. (source: wiki/sources/descriptions/gmh5225__blood-hunt.md) Title-specific Facepunch Rust external cheat samples such as [[rust-external-1]] (C++; kernel driver or RPM cross-process reads; Unity process; cheat / game:rust [External]; gmh5225) extend that lane as driver-backed externals under [[easy-anti-cheat]]. (source: wiki/sources/descriptions/gmh5225__rust-external-1.md) Title-specific Fortnite external cheat samples such as [[fortnite-external-cheat-winsense-leak]] (gmh5225; WinSense leak; kernel driver comm for cross-process memory access; CryptoPP-encrypted API anti-tamper; UE offset tables + external structure-read utilities; cheat / game:fortnite [External]) extend that lane beside Rust driver-backed externals. (source: wiki/sources/descriptions/gmh5225__Fortnite-External-Cheat-WinSense-Leak.md) Leaked Apple Lite Fortnite cheat remakes such as [[apple-lite-fortnite-cheat]] (gmh5225; Police remake; C/C++; kernel-level work + shader work + modding; cheat / game:fortnite) extend that lane beside [[serenity-gg-fn-and-loader]]. (source: wiki/sources/descriptions/gmh5225__Apple-Lite-Fortnite-Cheat.md) Title-specific Apex Legends fixed-cheat samples such as [[apex-cheat-fixed]] (gmh5225; C/C++; driver development / modding / hooking; cheat / game:apex legends) extend that lane beside [[apex-simple-aimbot-glow-apex]]. (source: wiki/sources/descriptions/gmh5225__Apex-CHEAT-FIXED.md) DayZ/Enfusion external ESP samples such as [[external-dayz-cheat]] (gmh5225; kernel driver entity reads via `Driver.h`; transparent D3D9 overlay; SDK offset entity-list walk; cheat / game:dayz [External]) sit in the same driver-backed external overlay lane. (source: wiki/sources/descriptions/gmh5225__External-Dayz-Cheat.md) Circa-2019 Fortnite externals such as [[fortnite-external-4]] (gmh5225; socket-based kernel driver for cross-process RPM; Capcom.sys-based driver mapper loads the comm driver; ESP/aimbot; cheat / game:fortnite [External]) illustrate legacy BYOVD manual-map + kernel-socket cheat comm beside IOCTL-backed externals. (source: wiki/sources/descriptions/gmh5225__Fortnite-External-4.md) Driver/shader/audio external source scaffolds such as [[rust-external-source]] (C/C++; driver development / shader work / audio systems; cheat / game:rust [External]; gmh5225) extend that lane beside overlay ESP samples. (source: wiki/sources/descriptions/gmh5225__Rust-External-Source.md) Driver/overlay/memory-analysis external scaffolds such as [[rust-external-and-driver-aliencheats]] (C++/C/C++; driver development / overlays / memory analysis; cheat / game:rust [External]; gmh5225) extend that lane beside overlay ESP samples. (source: wiki/sources/descriptions/gmh5225__Rust-ExternaL-and-Driver-AlienCheats.md) Facepunch Rust driver/modding/SDK external samples such as [[rust-cheat-external]] (C/C++; driver development / modding / SDK generation; cheat / game:rust [External]; gmh5225) extend that lane. (source: wiki/sources/descriptions/gmh5225__Rust-Cheat-External.md) Driver/rendering/Unity Facepunch Rust external samples such as [[rico-cheat-rust-external]] (C++/C/C++; driver development / rendering / Unity; cheat / game:rust [External]; gmh5225) extend that lane. (source: wiki/sources/descriptions/gmh5225__Rico-Cheat-rust-external.md) Title-specific Facepunch Rust kernel-assisted externals such as [[rust-external-cheat]] (bootmgfw; WDM **DriverRW** IOCTL cross-process R/W/alloc/module-base; usermode Rust SDK + entity loops; DX9 ImGui overlay; driver trace cleanup + kernel hooks; cheat / game:rust [External]) consume KM↔UM primitives beside [[lithium-kernel]] from the same author. (source: wiki/sources/descriptions/bootmgfw__Rust-External-Cheat.md) Title-specific Facepunch Rust kernel-assisted external samples such as [[overflow-rust]] (NMan1; C/C++; kernel driver + user-mode rendering client; kernel call-chain hook bypass via shared memory; ESP/recoil/automation modules; kernel hook + overlay RE; cheat / game:rust [External]) extend that lane beside [[rust-external-cheat]]. (source: wiki/sources/descriptions/NMan1__OverflowRust.md) Title-specific Facepunch Rust kernel-assisted external frameworks such as [[rust-cheat-external-main]] (Disline1337; Windows driver IOCTL process memory R/W + usermode overlay rendering and gameplay SDK helpers; UnityPlayer/GameAssembly module handling; cheat development experiments + external driver-assisted attack-pattern research; cheat / game:rust [External]) extend that lane beside [[lord-abbot-rust-external-cheat]] and [[overflow-rust]]. (source: wiki/sources/descriptions/Disline1337__Rust-Cheat-External-main.md) Title-specific Fortnite kernel-assisted externals such as [[fortnite-external-cheat-base]] (bootmgfw; C++; kernel-driver IOCTL phys mem R/W + CR3 bypass for [[easy-anti-cheat]] + synthetic mouse input; UE SDK + encrypted UWorld decode; DX11 ImGui overlay; cheat / game:fortnite [External]) consume the same KM↔UM lane beside [[lithium-kernel]] from the same author. (source: wiki/sources/descriptions/bootmgfw__Fortnite-External-Cheat-Base.md) Kernel modding and low-level research utilities such as [[r0ak]] (C/C++; kernel-level work and modding; Some Tricks / Windows Ring3; gmh5225) target Windows, Linux, and mobile researchers in the unconventional kernel research lane beside conventional driver-backed R/W samples. (source: wiki/sources/descriptions/gmh5225__r0ak.md) Per-process PTE hook samples such as [[windows-kernel-pagehook]] exploit shared kernel VA with distinct CR3 roots (Some Tricks / Windows Ring0 / PTE Hook). (source: wiki/sources/descriptions/stdhu__windows-kernel-pagehook.md) Hidden/shadowed memory region PoCs such as [[yumekage]] (Xyrem; C++; guarded-region techniques tied to context-switch behavior; demo code for runtime inspection evasion; Some Tricks / PTE Hook) (source: wiki/sources/descriptions/Xyrem__Yumekage.md) C++ PTE hooking demo [[page-table-hook]] (Rythorndoran; edits paging structures to redirect execution without direct code patches; `NtCreateFile` example; framed to avoid typical PatchGuard-triggering approaches; Some Tricks / PTE Hook) (source: wiki/sources/descriptions/Rythorndoran__PageTableHook.md) KPRCB **`IdlePreselect`** power-management callback hook PoCs such as [[powerhook]] (Archie-osu; C++ KMDF driver; rewires PRCB IdlePreselect while preserving original handler; thread/process lookups + execution-context logging; Windows internals / low-level game security research; README Hooking KPRCB IdlePreselect) (source: wiki/sources/descriptions/Archie-osu__PowerHook.md) **#PF page-fault hook** research such as [[fast-pf-hook]] (brew02; parse/relocate hooked-function instructions to a shadow page; execute via #PF exception handler; Some Tricks / Windows Ring0 / PF Hook) (source: wiki/sources/descriptions/brew02__FastPFHook.md) **SMAP/SMEP EPT-like inline hook** PoCs such as [[budget-ept]] (brew02; repurpose supervisor access/execution prevention to emulate split-page EPT hook semantics without a hypervisor; limited software-virtualization concealment example; Some Tricks / Windows Ring0) (source: wiki/sources/descriptions/brew02__BudgetEPT.md) KdTrap global exception-handler hooks such as [[hook-kdtrap]] (gmh5225; patch `HalpStallCounter` and related globals to hijack first-chance kernel exception dispatch; custom handler intercepts null derefs and reserved CR3-bit faults; Some Tricks / Ring0 exception research) (source: wiki/sources/descriptions/gmh5225__Hook-KdTrap.md) Global exception-hook chain driver [[hook-guard]] (SamuelTulach; C kernel driver; monitors and obfuscates process address-space switching via CR3/exception-dispatch/`KdpDebugRoutineSelect` paths; logs protected-context switch attempts; PatchGuard-aware + HVCI-compatible defensive AC research; cheat / Global exception/KdpDebugRoutineSelect) (source: wiki/sources/descriptions/SamuelTulach__HookGuard.md) Compact dependency-free kernel inline detour library samples such as [[driver-kdtour]] (gmh5225; `c_detour` saves stolen bytes, MDL-backed writable patch + absolute jump stub; sample hooks `KeAttachProcess`; targets like `MmCopyMemory`/`MmCopyVirtualMemory`; Easy Kernel Detour / Some Tricks) (source: wiki/sources/descriptions/gmh5225__Driver-KDtour.md) Defensive **KeAttachProcess** usage-detection PoCs such as [[detect-keattachprocess]] (KANKOSHEV; continuously running kernel driver; enumerates processes/threads and inspects thread context for unexpected attached target processes; anti-cheat / covert process-attachment monitoring research) complement offensive attach/hook lanes. (source: wiki/sources/descriptions/KANKOSHEV__Detect-KeAttachProcess.md) Educational documented **`MmCopyMemory`** hook sample such as [[simple-mmcopymemory-hook]] (Spuckwaffel; intentionally simple kernel driver; observe AC scanner memory-copy telemetry; unstable/detectable; learning kernel hook mechanics; README `[Hook MmcopyMemory]`) (source: wiki/sources/descriptions/Spuckwaffel__Simple-MmcopyMemory-Hook.md) Targeted **`MmCopyMemory`** scan-path bypass PoC [[mm-copy-memory]] (EBalloon; C++; explains kernel AC memory-scan behavior; minimal example patches a specific check path to alter scan handling; bypass research + defensive kernel memory-inspection study; cheat / Bypass MmCopyMemory) (source: wiki/sources/descriptions/EBalloon__MmCopyMemory.md) Kernel-thread driver + usermode controller such as [[kernel-thread-driver]] (Spuckwaffel; status-code KM↔UM comms; target process setup, memory read, module base retrieval; AC bypass research / kernel-user architecture experiments; README `[Thread]`) (source: wiki/sources/descriptions/Spuckwaffel__Kernel-Thread-Driver.md) `HvlSwitchVirtualAddressSpace` hooks such as [[hook-hvl-switch-virtual-address-space]] (gmh5225; intercept hypervisor-assisted address-space switches; manipulate CR3 transitions to hide pages from AC process memory scans during context switches; README `[HvcallCodeVa]`) (source: wiki/sources/descriptions/gmh5225__Hook-HvlSwitchVirtualAddressSpace.md) Hypercall-page dispatcher PoCs such as [[driver-hypercall-page-hook]] (gmh5225; replace `nt!HvcallCodeVa` near `HvlInvokeHypercall`; flip `HvlEnlightenments`; assembly dispatcher forwards selected hypercall codes and falls back to the original page; README `[HvcallCodeVa]`) (source: wiki/sources/descriptions/gmh5225__Driver-HypercallPageHook.md) Hook enumeration/removal tooling such as [[antihook]] (enum + remove hooks; driver / graphics) complements those install samples in the same offensive hook-management lane. (source: wiki/sources/descriptions/kouzhudong__AntiHook.md) Cross-platform page-table editors such as [[pteditor]] (Linux LKM + userspace lib + Windows driver; PGD/PUD/PMD/PTE R/W, VA→PA, PAT/NX/TLB; x86_64 + ARMv8) sit in the same PTE manipulation lane. (source: wiki/sources/descriptions/misc0110__PTEditor.md) Live process page-table browsers such as [[ptview]] (VollRagm; C++ kernel driver + C# GUI; browse entries, dump physical pages, inspect PTE metadata, VA→PA translation, large-page awareness; OS memory research / debugging / AC kernel investigations) complement editors in the inspection lane. (source: wiki/sources/descriptions/VollRagm__PTView.md) Kernel-mode RWX mapping scanners such as [[rwxscanner]] (Oliver-1-1; enumerates process page tables via physical reads; flags writable+executable regions and process metadata; AC/malware detection research; README [RWX Memory scanner]) extend page-table inspection toward suspicious PTE protection analysis. (source: wiki/sources/descriptions/Oliver-1-1__RwxScanner.md) Page-table injection research such as [[page-table-injector]] (C/C++; kernel driver; cheat / injection:windows; page-table manipulation / AC research) (source: wiki/sources/descriptions/isiddique2024__Page-Table-Injector.md); PTE.User page-table injection samples such as [[executor]] (C/C++; pTE.User; driver development; cheat / injection:windows; gmh5225) (source: wiki/sources/descriptions/gmh5225__executor.md) and [[fumo-loader]] (C/C++; pTE.User; kernel driver; anti-cheat research; cheat / injection:windows; dumbasPL) (source: wiki/sources/descriptions/dumbasPL__fumo_loader.md); Physical-memory reads via manual PTE mapping without `MmCopyMemory`/`MmMapIoSpace` such as [[readphys]] (reversed from `AXE-BASE.sys`; ACE explore) sit in the same PTE / phys-read lane. (source: wiki/sources/descriptions/rogxo__ReadPhys.md) Scriptable kernel research drivers such as [[pawnio]] (namazso; WDK C++20 driver embedding Pawn AMX VM; signed bytecode modules via IOCTL; phys/virt memory, MSR/PCI/CPUID/CR/DR, I/O ports, SMM; SHA-256 + trusted-key module auth; kernel RE lane) offer rapid low-level hardware probing without rebuilding the driver per experiment. (source: wiki/sources/descriptions/namazso__PawnIO.md) Minimal PTE-PFN rewrite + manual VA→PA cross-process copy teaching samples such as [[driver-rpm-direct-page-manipulation]] (gmh5225; allocate page → locate own PTE → remap PFN → target module read without documented copy helpers; README `[read physical memory]`) (source: wiki/sources/descriptions/gmh5225__Driver-RPM-DirectPageManipulation.md) EAC-focused CR3 bypass teaching samples such as [[eac-cr3-bypass]] (C/C++; UM+KM; cheat / explore anticheat system:eac) sit in the same CR3 / page-table evasion lane. (source: wiki/sources/descriptions/kprprivate__EAC-CR3-BYPASS.md) Compact CR3-shuffle research sample [[eac-cr3-shuffle]] (SamuelTulach; C++; physical memory range walk, directory-base discovery, VA→PA translation checks; reference on CR3 manipulation vs external memory inspection; cheat / Bypassing CR3 protection) documents EAC CR3 shuffling for paging/anti-cheat internals study. (source: wiki/sources/descriptions/SamuelTulach__eac_cr3_shuffle.md) Kernel driver PoC [[enum-real-dirbase]] (Rythorndoran; C++ WDK; PFN database traversal + physical range walk to enumerate real process CR3/dirbase; self-referencing page tables + runtime MmPfnDatabase resolve; kernel AC research / memory forensics / hidden address-space tracking; cheat / Find real dirbase) documents PFN-backed directory-base recovery beside shuffle-focused samples. (source: wiki/sources/descriptions/Rythorndoran__enum_real_dirbase.md) Hybrid usermode NT-API interception + kernel-driver redirect samples such as [[intraceptor]] (crvvdev; intercept Windows NT calls and redirect to a kernel driver to bypass process/thread handle protections; cheat / access) sit in the same AC handle-protection bypass lane beside [[libelevate]]. (source: wiki/sources/descriptions/crvvdev__intraceptor.md) Driver+DLL handle acquisition bypassing ObRegisterCallbacks via kernel `ObOpenPointerToObject` + usermode `OpenProcess` hook such as [[easy-handles]] (AlSch092; IOCTL-forwarded requests; debugger attach to callback-protected processes; PPL limitations noted; AC/EDR handle-protection research) (source: wiki/sources/descriptions/AlSch092__EasyHandles.md) extends that lane. BTBD [[access]] (kernel syscall hook via `.data` section modification; usermode DLL wrapper; handleless `PROCESS_ALL_ACCESS` on protected game processes; syscall-hook / process-protection bypass research; cheat / access) extends that lane without creating observable process handles. (source: wiki/sources/descriptions/btbd__access.md) Updated fork [[access-updated]] (bromoket; Zydis dynamic pattern finding; Win10 1607+–Win11 24H2; `xKdEnumerateDebuggingDevices` `.data` hook; no inline patches) extends that handleless access lane with cross-build compatibility. (source: wiki/sources/descriptions/bromoket__access_updated.md) Archived PUBG internal cheat stacks such as [[pubg-internal]] (ajkhoury; kernel driver for protected-process mapping + SDK generator + in-process ESP; historical UM+KM cheat architecture study; cheat / game:pubg) illustrate end-to-end protected-title internals beside driver-only R/W samples. (source: wiki/sources/descriptions/ajkhoury__pubg_internal.md) Rust PUBG external frameworks such as [[valthrun-pubg]] (Valthrun; Zenith kernel-driver IOCTL memory R/W; CR3 manipulation for process-protection bypass; synthetic keyboard/mouse input; ESP/radar; cheat / game:pubg [External]) consume the same CR3 / cross-process KM lane. (source: wiki/sources/descriptions/Valthrun__Valthrun_PUBG.md) C++ PUBG external assistance references such as [[pubg-public]] (K-cazb; driver-assisted memory access + decryption helpers for protected-process external reads; cheat / game:pubg [External]) consume the same cross-process KM lane. (source: wiki/sources/descriptions/K-cazb__pubg-public.md) Rust CS2 external read-only kernel frameworks such as [[valthrun]] (Valthrun; kernel driver + overlay renderer + radar; no in-process DLL injection; ESP/bomb/spectator/trigger + stream-proof overlay; cheat / game:cs2 [External]) sit in the same non-injecting external KM lane. (source: wiki/sources/descriptions/Valthrun__Valthrun.md) - **[[kernel-callbacks]]:** process/thread/image notify, ObRegisterCallbacks, Cm/Flt; reference callback API catalog such as [[kernel-callback-functions-list]] (gmh5225; documentation; anti-cheat / Ring0 callback lane) (source: wiki/sources/descriptions/gmh5225__kernel-callback-functions-list.md); executive callback object research collection such as [[executive-callback-objects]] (0xcpu; C kernel PoCs + notes; register/inspect/analyze callback activity across networking, system state, boot, and security families; Windows internals / telemetry visibility / AC+EDR analysis; README Callback) (source: wiki/sources/descriptions/0xcpu__ExecutiveCallbackObjects.md); reusable implementation snippets such as [[kernel-snippets]] (gmh5225; callback registration, memory ops, process manipulation; incl. VGK SwapContext hook sample; Some Tricks / driver dev) (source: wiki/sources/descriptions/gmh5225__KernelSnippets.md); ETW/CKCL **SwapContext** scheduling-hook PoC such as [[hook-swap-context]] (1401199262; C++ kernel driver; custom stack-frame checks invoke handler during selected scheduling flow; README SwapContext hook) (source: wiki/sources/descriptions/1401199262__HookSwapContext.md); debug print callback PoCs such as [[detection-cheat-engine-ring0]] (gmh5225; `DbgSetDebugPrintCallback` string filter for `dbvm-mode`; Cheat Engine / DBVM detection experiment) (source: wiki/sources/descriptions/gmh5225__Detection-CheatEngine-Ring0.md); `KeRegisterBoundCallback` research such as [[boundcallback]] (C++; cheat / driver communication) (source: wiki/sources/descriptions/sbsbsbssbsbs__boundcallback.md); `CmRegisterCallback` registry-callback JMP RCX hijack PoCs such as [[common-registry-jmp-rcx]] (gmh5225; `JMP RCX` gadget in `nvraid.sys`; redirect callback dispatch to custom handler for covert KM↔UM comm; README `[Registry Callback]`) (source: wiki/sources/descriptions/gmh5225__Common-Registry-Jmp-RCX.md); KMDF registry-callback KM↔UM PoC such as [[common-registry]] (EBalloon; C++ KMDF driver + user client; custom process-attach handling and low-level memory-management ideas; Windows internals / AC bypass research; README `[Registry Callback]`) (source: wiki/sources/descriptions/EBalloon__Common-Registry.md); registry-callback KM↔UM PoC for manually mapped drivers via jump gadget in a legitimate module such as [[registry-callbacks]] (0xGREG; C/C++ kernel + user-mode; virtual/protected memory R/W, process-base lookup, heartbeat; kernel communication / AC evasion research; README `[Registry Callback]`) (source: wiki/sources/descriptions/0xGREG__registry-callbacks.md); hide-callback codecave JMP samples such as [[mapped-callback]] (APCI cave → valid-module start address; cheat / hide) (source: wiki/sources/descriptions/nlepleux__MappedCallback.md); anti-cheat callback/integrity-hook PoCs such as [[pink-eye]] (SurgeGotTappedAgain; Ob callback code-cave redirect + integrity-check path tampering; KMDF-style driver; AC research) (source: wiki/sources/descriptions/SurgeGotTappedAgain__Pink-Eye.md); defensive enumeration/inspection via anti-rootkit GUIs such as [[openark]] (SSDT/shadow SSDT, drivers, objects) and Object Manager explorer [[winobjex64]] (namespace browse + callback enum; admin; AC / Ring0 callback research) (source: wiki/sources/descriptions/hfiref0x__WinObjEx64.md); driver-backed sibling [[object-explorer]] (Object Manager namespace/handles/types; PDB/DIA kernel structure decode; security descriptors + access masks; zombie-process detect; zodiacon) (source: wiki/sources/descriptions/zodiacon__ObjectExplorer.md); object-symlink access callbacks such as [[symlink-callback]] (LinkTarget → callback) (source: wiki/sources/descriptions/yyl-20020115__OpenArk.md) (source: wiki/sources/descriptions/yardenshafir__SymlinkCallback.md); process/file protection via FSFilter minifilter + access-blocking drivers such as [[vaultguard]] (pure x64 MASM; hide/lock/RO/block-exec; anti-debug tray GUI) (source: wiki/sources/descriptions/wesmar__VaultGuard.md); offensive kernel file-hide samples such as [[hide-file]] (C driver; cheat / hide) (source: wiki/sources/descriptions/sina85__hide-file.md); integrated minifilter stealth + MDL memory framework [[memfilter-fn-driver]] (zensenzay; Flt/Cm/Ob callbacks; Filter Manager port comm; cheat / hide + RPM) (source: wiki/sources/descriptions/zensenzay__memfilter-fn-driver-.md); Rust minifilter-abuse concealment PoCs such as [[puzzle]] (Kudaes; bind links, ID mapping, cloud sync providers, WIM hash manipulation; stealth post-exploitation; cheat / hide) (source: wiki/sources/descriptions/Kudaes__Puzzle.md); driver-list unlink via Flink/Blink such as [[hide-driver]] (cheat / hide; AC enum evasion) (source: wiki/sources/descriptions/nbqofficial__HideDriver.md); multi-artifact driver-hide stress tests such as [[hide-driver-testing]] (gmh5225; MmUnloadedDrivers, PsLoadedModuleList, PiDDBCacheTable, driver object lists; Win11 21H2; cheat / hide) (source: wiki/sources/descriptions/gmh5225__HideDriverTesting.md); unsigned-driver load + identity camouflage research such as [[drv-hide-and-camouflage]] (IcEy-999; C ring-0; unexported kernel routines, manual offset init, object/import-table manipulation; modern Windows version tests; README Hide Driver) (source: wiki/sources/descriptions/IcEy-999__Drv_Hide_And_Camouflage.md); `MiProcessLoaderEntry` / `DriverSection` hide PoCs such as [[hidedriver]] (ExpLife0011; ETW symbol discovery; PatchGuard-aware `DriverObject->DriverSection` removal; post-load artifact cleanup thread; anti-cheat evasion / driver forensics research; README `[Hide Driver By MiProcessLoaderEntry]`) (source: wiki/sources/descriptions/ExpLife0011__HideDriver.md); process-hide samples such as [[blanket]] (ActiveProcessLinks unlink + PspCidTable patch + `NtQuerySystemInformation` hook; cheat / hide) (source: wiki/sources/descriptions/kitty8904__blanket.md); process/file obfuscation via write→map→modify→execute such as [[herpaderping]] (`SEC_IMAGE` mapping + process-creation callback timing; on-disk decoy vs mapped image; cheat / hide) (source: wiki/sources/descriptions/jxy-s__herpaderping.md); process cloning via `NtCreateProcessEx` such as [[process-cloning]] (C PoC; parent-handle VA-space snapshot; process hollowing / memory analysis / credential dump from clone without direct target access) (source: wiki/sources/descriptions/huntandhackett__process-cloning.md); kernel APC DLL injection on process-create notify such as [[injdrv]] (`LdrLoadDll` via queued user APC) (source: wiki/sources/descriptions/wbenny__injdrv.md); map + APC kernel inject samples such as [[kinject]] (cheat / injection:windows) (source: wiki/sources/descriptions/w1u0u1__kinject.md); Sirifef-inspired kernel DLL inject on kernel32 load such as [[kernel-dll-injector]] (alexkrnl; inject chosen DLL when kernel32 loads in new processes; driver + sample DLL; x86; Visual Studio/WDK; APC; kernel-assisted injection / defensive detection research) (source: wiki/sources/descriptions/alexkrnl__Kernel-dll-injector.md); [[kdmapper]]-loaded kernel manual-map DLL injectors such as [[kernelmode-dll-injector]] (YouNeverKnow00; Intel vulnerable driver → custom KM driver; PE section map + import/reloc/TLS + IOCTL comms; Manual Map; kernel-assisted injection / BYOVD process manipulation research) (source: wiki/sources/descriptions/YouNeverKnow00__Kernelmode-DLL-Injector.md); early-startup kernel DLL injection frameworks such as [[kmdllinjector]] (0xPrimo; C++; process/image-load callback triggering; ntdll loader hook with position-independent shellcode; kernel APC injection path; advanced process injection research in controlled security testing; kernel-mode DLL Injector) (source: wiki/sources/descriptions/0xPrimo__KMDllInjector.md); BYOVD DLL injectors bundling multiple WHQL-signed vulnerable drivers such as [[zhangbing-injector]] (M3351AN; C++ usermode + bundled `.sys` drivers; driver-mediated memory ops + protected-process DLL injection; credits [[kdmapper]]; kernel-assisted injection research) (source: wiki/sources/descriptions/M3351AN__ZhangBing-Injector.md); kernel-mode IAT manual-map injectors such as [[kernelmode-manual-mapping-through-iat]] (process handle or companion kernel driver; IAT Manual Map) (source: wiki/sources/descriptions/mactec0__Kernelmode-manual-mapping-through-IAT.md); APC internals research samples/library such as [[apc-research]] (cheat / windows kernel explorer) (source: wiki/sources/descriptions/repnz__apc-research.md); *Practical Reverse Engineering* textbook solutions via [[practical-reverse-engineering-solutions]] (DPC/APC and kernel-analysis exercises with annotated disassembly; cheat / guide; gmh5225) (source: wiki/sources/descriptions/gmh5225__Practical-Reverse-Engineering-Solutions.md); stealth APC dispatch with encrypted shellcode such as [[stealth-apc-dispatcher]] (gmh5225; non-standard queue paths; cheat / injection:windows / AC APC monitoring bypass research) (source: wiki/sources/descriptions/gmh5225__StealthAPCDispatcher.md); special-kernel-APC cross-process read teaching sample such as [[kernel-special-apc-readprocessmemory]] (gmh5225; `KeInitializeApc`/`KeInsertQueueApc`; runnable-thread APC delivery; nonpaged staging + callback memcpy vs RPM benchmark; cheat / RPM) (source: wiki/sources/descriptions/gmh5225__Kernel-Special-APC-ReadProcessMemory.md); thread-description APC working-set probes such as [[thread-namecalling]] (`SetThreadDescription` + remote `GetThreadDescription`; cheat / injection:windows) (source: wiki/sources/descriptions/hasherezade__thread_namecalling.md); BattlEye BEDaisy APC instrumentation such as [[goodeye]] (kernel callback on each BE-registered APC thread; cheat / explore anticheat system:be) (source: wiki/sources/descriptions/huoji120__goodeye.md); BEDaisy interception PoC such as [[bedaisy]] (Aki2k; C++; image-load callbacks + IAT hook around MmGetSystemRoutineAddress; APC experimentation; kernel AC bypass-surface RE) (source: wiki/sources/descriptions/Aki2k__BEDaisy.md); NMI callback kernel driver research such as [[nmi-callback]] (C/C++; `KeRegisterNmiCallback` lane; Detection: Hacked Hypervisor / AC defensive study) (source: wiki/sources/descriptions/helloobaby__Nmi-Callback.md); NMI disable/block PoCs such as [[nmi-callback-blocker2]] (C++; disable NMI callbacks; cheat / windows kernel explorer; gmh5225) (source: wiki/sources/descriptions/gmh5225__NMICallbackBlocker2.md); [[disable-nmi-callbacks]] (kernel driver; KiNmiInterruptStart pattern scan in ntoskrnl; patch processor affinity + NMI state vs NMI stack-walk AC; gmh5225) (source: wiki/sources/descriptions/gmh5225__Disable-nmi-callbacks.md); [[nmi]] (ekknod; C/C++; block NMI interrupts vs NMI stack-walk AC; cheat / windows kernel explorer) (source: wiki/sources/descriptions/ekknod__Nmi.md); NMI register/trigger PoCs such as [[nmi-nmi-callback]] (C/C++; register/use NMI callbacks + cross-CPU thread-context inspection; BattlEye-style detection study; cheat / windows kernel explorer; gmh5225) (source: wiki/sources/descriptions/gmh5225__NMI-nmi_callback.md); NMI interrupted-RIP / MACHINE_FRAME stack-walk PoCs such as [[nmi-callback-handler]] (donnaskiez; recover interrupted RIP from iretq MACHINE_FRAME; cross-CPU suspicious-memory execution detect; Mapped Driver by NMI Callback; defensive AC study) (source: wiki/sources/descriptions/donnaskiez__nmi-callback-handler.md); NMI stack-backtrace PoC such as [[nmi-stack-walk]] (1401199262; NMI to selected CPUs + stack walk in callback; hidden no-module driver detect; C VS kernel driver; README Mapped Driver by NMI Callback) (source: wiki/sources/descriptions/1401199262__NMIStackWalk.md); open-source multi-detector kernel AC driver [[ac]] (donnaskiez; NMI/APC/DPC stack walks, `.text` integrity, ObRegisterCallbacks handle strip, chained data-pointer detect, attached-thread / return-address hook / module device / handle-table checks; defensive AC research) (source: wiki/sources/descriptions/donnaskiez__ac.md); NMI enumeration PoCs such as [[nmi-enum-nmi-callback]] (C/C++; enumerate registered NMI callbacks; cheat / windows kernel explorer; gmh5225) (source: wiki/sources/descriptions/gmh5225__NMI-EnumNmiCallback.md); rootkit-style process/callback manipulation utilities such as [[rtoolz]] (gmh5225; driver-backed hide/unhide processes, kernel callback enum/removal, notification-routine removal, process protection-level changes; `ProcExp152.sys` backend; kernel researcher tool) (source: wiki/sources/descriptions/gmh5225__RToolZ.md); kernel rootkit/driver frameworks such as [[fenrir]] (gmh5225; process hide, memory access, callback management; README stack spoof via `jmp rdi`; research rootkit framework) (source: wiki/sources/descriptions/gmh5225__Fenrir.md); focused notify-routine unloaders such as [[ps-notif-routine-unloader]] (gmh5225; enumerate/remove process/thread/image notify callbacks from AC/security drivers via `PsSetCreateProcessNotifyRoutine`; `RTCore64.sys` backend) (source: wiki/sources/descriptions/gmh5225__PsNotifRoutineUnloader.md); dynamic callback-list discovery such as [[dcmb]] (GetRektBoy724; C kernel driver; locates process/thread/image/registry/object/minifilter callback lists without hardcoded offsets or signatures; debug-output learning PoC; AC/EDR callback inspection; README Removing kernel callbacks) (source: wiki/sources/descriptions/GetRektBoy724__DCMB.md); dedicated-thread `PspCreateThreadNotifyRoutine` hijack PoCs such as [[notify-routine-hijack-thread]] (UCFoxi; compact Visual Studio C++ driver sample; callback manipulation showcase; anti-cheat / EDR evasion research; README [Hijack PspCreateThreadNotifyRoutine]) (source: wiki/sources/descriptions/UCFoxi__NotifyRoutineHijackThread.md); BAM extension-table process-notify hook PoCs such as [[bam-extension-table-hook]] (Dor00tkit; swaps `bam!BampCreateProcessCallback` on extension-host path vs standard notify array; ntoskrnl offset lookup + notify-mask handling; AC/EDR callback bypass research; README [bam!BampCreateProcessCallback]) (source: wiki/sources/descriptions/Dor00tkit__BamExtensionTableHook.md); BYOVD callback enum/modify PoCs such as [[cheeky-blinder]] (br-sn; signed vulnerable MSI driver; enumerate and modify kernel callbacks; cheat / windows kernel explorer) (source: wiki/sources/descriptions/br-sn__CheekyBlinder.md); system-wide kernel DLL inject + function-hook drivers such as [[kptnhook]] (every process from early boot; cheat / injection:windows) (source: wiki/sources/descriptions/sum-catnip__kptnhook.md); CS2 client-side KMDF AC companion [[cs2kac]] (ObRegisterCallbacks, image/process notify, thread creation; ring-buffer detection reports over IOCTL to usermode service attached to `cs2.exe`) (source: wiki/sources/descriptions/speedskater1610__CS2KAC.md); demand-start defensive reference [[oac]] (lauralex; Open Anti-Cheat — ObRegisterCallbacks handle policy, user-mode preflight/suspended launch, cross-view integrity checks) (source: wiki/sources/descriptions/lauralex__OAC.md); open-source user-mode AC framework [[ultimate-anti-cheat]] (AlSch092; C++; debug/memory-patch/runtime tamper detection; optional client-server heartbeat; configurable hybrid user-mode + kernel-assisted deployment; educational AC evaluation reference) (source: wiki/sources/descriptions/AlSch092__UltimateAntiCheat.md); educational full-stack AC reference [[peregrine-anticheat]] (PatchRequest; kernel minifilter + ObCallbacks + APC injection + ETW-TI + MinHook; in-process YARA/stack/HWBP agent with named-pipe backend; Tauri GUI + cheat test suite) (source: wiki/sources/descriptions/PatchRequest__PeregrineAntiCheat.md); defensive injection-blocking driver [[pi-defender]] (PI-Defender; C++ WDK driver; filters remote memory-write and related handle rights on protected processes; docs/tests for hollowing, doppelgänging, ghosting, and DLL injection; anti-cheat-style hardening research) (source: wiki/sources/descriptions/PI-Defender__pi-defender.md); kernel callout / spoof-stack PoCs such as [[callout-poc]] (C/C++; kernel debug) (source: wiki/sources/descriptions/thesecretclub__callout-poc.md) - **Process / system explorers:** host inspection tools such as [[systeminformer]] (formerly Process Hacker) for process/handle/module analysis in the Cheat Windows kernel explorer lane. (source: wiki/sources/descriptions/winsiderss__systeminformer.md) Agent-facing Process Hacker–style runtime analysis via [[processhacker-mcp]] (MCP server; C/C++; DLL plugin extensibility; Game Develop / MCP) extends that explorer lane for AI-driven process hacking. (source: wiki/sources/descriptions/illegal-instruction-co__processhacker-mcp.md) Procmon-style real-time activity monitors such as [[openprocmon]] (C++; ETW + minifilter; process/file/registry/network/DLL; filter/highlight/export GUI) sit in the same explorer / telemetry lane. (source: wiki/sources/descriptions/progmboy__openprocmon.md) Qt ARK-style comprehensive system analysis toolkits such as [[ksword]] (KSwordDEV; C++ Qt GUI + custom kernel driver; modular panels for processes, kernel objects, memory, drivers, callbacks, SSDT hooks, network, crash dumps, and file-system artifacts; Win32 API inline-hook monitor, Cheat Engine plugin, DWM layer control, VirusTotal/ThreatBook scanning; game-security / Windows internals RE; cheat / Windows Kernel Explorer [ARK]) (source: wiki/sources/descriptions/KSwordDEV__KSword.md) Virtualization-based ProcMon-style kernel tracers such as [[kernelmon]] (alal4465; VMX/EPT low-level interception; hooks selected kernel-mode APIs → usermode desktop UI; file/registry/process/thread coverage; kernel security / AC / malware behavior analysis in controlled VMs) extend that lane beyond ETW/minifilter telemetry. (source: wiki/sources/descriptions/alal4465__KernelMon.md) Named-pipe enumeration GUIs such as [[pipeviewer]] (CyberArk; C#; security descriptors, clients, access modes, owning process; filter/search; real-time pipe create/delete monitoring; Windows IPC attack-surface study) extend that lane to live `\Device\NamedPipe\` instance inspection. (source: wiki/sources/descriptions/cyberark__PipeViewer.md) User-mode recursive directory watchers such as [[readdirectorychanges]] (C++ `ReadDirectoryChangesW` wrapper; async I/O + buffer management; create/modify/delete/rename events) sit in the same file-telemetry lane without requiring a minifilter driver. (source: wiki/sources/descriptions/jimbeveridge__readdirectorychanges.md) Defensive CLR assembly-load monitoring via [[clrguard]] (ClrHook DLL hooks intercept CLR initialization; block or log loaded assemblies with PE metadata/hashes; optional Windows service). (source: wiki/sources/descriptions/endgameinc__ClrGuard.md) Pre-modification backup tooling such as [[minivers]] (automatic backup copy before monitored file change/delete/rename; AC / backup-file lane) complements reactive directory-watch telemetry. (source: wiki/sources/descriptions/guidoreina__minivers.md) Async Cobalt Strike BOF USB hotplug monitors such as [[usb-monitor-bof]] (`WM_DEVICECHANGE`; device info + storage-volume actions; Some Tricks / Windows Ring3) extend that user-mode telemetry lane to removable-device attach/detach. (source: wiki/sources/descriptions/jakobfriedl__usb-monitor-bof.md) Broader UM+KM+UEFI research frameworks such as [[dioprocess-private]] (Rust/Dioxus process/handle/module/network monitor; kernel events → SQLite; DSE/KPP bootkit path; Win10 22H2 IOCTL research) sit in the same explorer / internals lane. (source: wiki/sources/descriptions/un4ckn0wl3z__dioprocess-private.md) TrustedInstaller-token launchers such as [[cmdt]] (hand-coded x86/x64 asm; token duplication + privilege enablement) reach TI-ACL–protected OS components when SYSTEM alone is insufficient. (source: wiki/sources/descriptions/wesmar__CmdT.md) User-mode access-token manipulation samples such as [[manipulating-token]] (C/C++; steal/duplicate/modify process tokens; SeDebugPrivilege; SYSTEM integrity-level LPE; gmh5225) illustrate generic privilege-escalation and impersonation primitives beside TI-token launchers. (source: wiki/sources/descriptions/gmh5225__manipulating_token.md) Windows Driver Development documentation guides such as [[document]] sit in the same Cheat / Windows kernel explorer learning lane. (source: wiki/sources/descriptions/supermanc88__Document.md) Curated kernel-internals index [[winkernel-resources]] (NullArray; papers, talks, vulnerable-driver references, practical links; sample driver VS solutions; offensive/defensive study; cheat / Guide) complements scattered guides in that lane. (source: wiki/sources/descriptions/NullArray__WinKernel-Resources.md) Kernel-space process dumpers such as [[nemesis]] sit in that same explorer / offensive dump lane. (source: wiki/sources/descriptions/not-matthias__Nemesis.md) Original C++ kernel-assisted dumpers such as [[ks-dumper]] (EquiFox; custom driver + usermode client; main-module PE32/64 rebuild; restricted-handle / AC-protected targets; driver load + dump workflow docs) and classic GUI + custom-driver forks such as [[ksdumper-11]] (C# UI + `KsDumperDriver.sys` IOCTL; KDU [[byovd]] load for DSE bypass; PE32/64 parse; undocumented NT process enum; Vulnerable Driver Blocklist registry patches) extend that lane. (source: wiki/sources/descriptions/EquiFox__KsDumper.md) (source: wiki/sources/descriptions/mastercodeon314__KsDumper-11.md) (source: wiki/sources/descriptions/mastercodeon314__KsDumper-11.md) - **Offline memory forensics:** RAM-image frameworks such as [[volatility]] (Python 2; profile-based; modules/rootkit plugins) and [[volatility3]] (Python 3; plugin-based process/network/registry/kernel-object extraction; automagic OS profiles) support post-compromise kernel-state analysis without live attach. (source: wiki/sources/descriptions/volatilityfoundation__volatility.md) (source: wiki/sources/descriptions/volatilityfoundation__volatility3.md) MemProcFS-based automated Windows dump analysis via [[memprocfs-analyzer]] (PowerShell; processes/network/registry/event logs/browser artifacts/malware indicators; HTML reports; VirusTotal TI; AC / IS forensics). (source: wiki/sources/descriptions/evild3ad__MemProcFS-Analyzer.md) Live full physical-memory capture via [[dumpit-mirror]] (Comae DumpIt mirror; one-click raw or Microsoft crash-dump output for Volatility / WinDbg; portable IR acquisition). (source: wiki/sources/descriptions/h4sh5__DumpIt-mirror.md) DIY live system memory dumps via [[tool-diy-system-memory-dump]] (gmh5225; crash-dump–compatible physical RAM from running Windows; WinDbg / Volatility offline analysis; Cheat DIY Dump Type). (source: wiki/sources/descriptions/gmh5225__Tool-DIYSystemMemoryDump.md) Pre-OS firmware offline crash dumps via [[offline-crash-dump-uefi]] (Microsoft EDK2 package; DXE `OfflineDumpWrite.efi`; dump partition + Windows UEFI variables; buffering/encryption/redaction; bring-up/platform-engineering reference; gmh5225). (source: wiki/sources/descriptions/gmh5225__OfflineCrashDumpUefi.md) USB-boot UEFI physical RAM dump app via [[memory-dump-uefi]] (NoInitRD; C UEFI application; live-boot USB + UEFI shell; scripts/build/docs for memory-image collection; forensic acquisition / low-level security research; README [A UEFI application for dumping the contents of RAM]). (source: wiki/sources/descriptions/NoInitRD__Memory-Dump-UEFI.md) VMware vTPM-encrypted snapshot decryptors such as [[vmem-decrypt]] (pure-Python encobj AES-256-CBC; decrypt `.vmem`/`.vmsn`/`.vmss`/`.nvram` from VM password; `vmem_flatten.py` → Volatility 3-ready image; Win11 partial VM encryption; AC / IS forensics). (source: wiki/sources/descriptions/heeeyaaaa__vmem-decrypt.md) Multiplatform `MEMORY.DMP` analysis with a WinDbg flavor via [[ephemera]] targets faster dump inspection for AC / kernel researchers when WinDbg itself is slow. (source: wiki/sources/descriptions/vmi-rs__ephemera.md) Python minidump readers such as [[minidumpreader]] sit in the same AC / Windows kernel dump-analysis lane. (source: wiki/sources/descriptions/tasox__miniDumpReader.md) Cross-platform minidump parse libraries such as [[minidump]] (skelsec; process memory / threads / modules / exceptions; LSASS dump automation without WinDbg) extend that lane for IR and credential-extraction scripts. (source: wiki/sources/descriptions/skelsec__minidump.md) C/C++ minidump format libraries such as [[libmdmp]] (libyal; memory analysis / debugging; AC / Windows kernel dump analysis) offer native parse tooling in the same lane. (source: wiki/sources/descriptions/libyal__libmdmp.md) Cross-platform C++ user-mode minidump parsing via [[udmp-parser]] (0vercl0k; threads/register contexts/virtual memory/modules; library API + parser utility; optional Python bindings; debugger tooling / dump triage) extends native parse tooling in the same lane. (source: wiki/sources/descriptions/0vercl0k__udmp-parser.md) Cross-platform C++ Windows kernel crash-dump parsing via [[kdmp-parser]] (0vercl0k; full/active dump formats; context/exception/bugcheck params + physical memory views; library API + parser CLI; optional Python bindings; crash forensics / kernel debug automation / exploitation RE) complements user-mode minidump tooling in the same lane. (source: wiki/sources/descriptions/0vercl0k__kdmp-parser.md) Windows execution-trace symbolization via [[symbolizer]] (0vercl0k; C++ CLI; dbgeng + crash-dump data resolve raw instruction pointers to function-level symbols; crash triage, exploit debugging, postmortem trace workflows) complements dump parse tooling in the same lane. (source: wiki/sources/descriptions/0vercl0k__symbolizer.md) WinDbg VM snapshot capture via [[snapshot]] (0vercl0k; Rust WinDbg extension; JSON CPU state + physical memory crash dump; full-kernel/active-kernel modes; snapshot-based fuzzing companion to [[wtf]]) freezes live VM execution for offline kernel RE. (source: wiki/sources/descriptions/0vercl0k__snapshot.md) Ghidra minidump loader extensions such as [[ghidra-minidump-loader]] (Rantanen; Java Gradle; runtime module mapping, private memory/thread stack import, thread metadata + stack-walk workflow; AC / crash-dump static RE in Ghidra) (source: wiki/sources/descriptions/Rantanen__ghidra-minidump-loader.md) Unicorn-based offline code execution from dumps via [[dumpulator]] (Python; reconstruct layout / syscall stubs / PEB·TEB; API hooking for function replay) supports AC / kernel RE when live attach is unavailable. (source: wiki/sources/descriptions/mrexodia__dumpulator.md) Full userspace PE emulation via [[sogen]] (Unicorn + Capstone; minidump load; Zstd state serialization; web UI + FlatBuffers trace IPC) offers the same offline lane with checkpointed interactive sessions. (source: wiki/sources/descriptions/momo5502__sogen.md) Debugger-emulator PE replay via [[emulator]] (Unicorn + Capstone; dbghelp imports; Windows API hooking; instruction-level logging for obfuscated/DRM binaries) extends the same Windows User Space Emulator offline lane. (source: wiki/sources/descriptions/mojtabafalleh__emulator.md) On Linux/KVM hosts, live Windows-guest kernel introspection without in-guest agents via [[memflow-kvm]] (memflow connector; maps KVM guest physical pages to userspace; page-table walk + vmtools; Rust bindings) offers an alternate to full RAM snapshots when analyzing Windows VMs in QEMU/KVM labs. (source: wiki/sources/descriptions/memflow__memflow-kvm.md) External-VM EAC kernel dossiers such as [[all-about-eac]] (BishopTopG; Memflow passive physical-memory acquisition from outside a Windows VM; PDB-matched mapping of one captured `EasyAntiCheat_EOS.sys` build's callback/minifilter/device IPC surfaces; evidence-labeled defensive RE with Python validation—no bypass material) apply the same out-of-guest Memflow lane to anti-cheat driver registration study. (source: wiki/sources/descriptions/BishopTopG__all-about-eac.md) Fleet-scale remote live acquisition via [[grr]] (Google GRR Rapid Response; Python server + HTTP endpoint agents; live memory, registry, and artifact collection orchestrated from a web UI; AC / IS forensics). (source: wiki/sources/descriptions/google__grr.md) - **Trust features:** DSE, PatchGuard, **VBS** (VTL0 normal world vs VTL1 Secure Kernel via hypervisor; memory-protection bucket includes [[hvci]]); VTL1 **Isolated User Mode (IUM) trustlet** debugging via [[ium-debugger]] (.NET; Hyper-V hypercalls for trustlet memory R/W + disassembly; LiveCloudKd `hvmm.sys` host-side patch of guest securekernel debug check so WinDbg in the guest attaches to VTL1 IUM trustlets) (source: wiki/sources/descriptions/ReverseWarrior__IUM-Debugger.md), Secure Boot; SMEP (Supervisor Mode Execution Prevention) CR4-disable PoCs such as [[smep-bypass]] (ROP / vulnerable-driver primitives → kernel exec of user shellcode) (source: wiki/sources/descriptions/r0keb__Smep-Bypass.md); Linux Authenticode/PKCS#7 signing of UEFI PE-COFF bootloaders and kernels via [[pesign]] (NSS cert DBs; distro Secure Boot signing infra) (source: wiki/sources/descriptions/rhboot__pesign.md); cross-platform Authenticode signing for PE and related Windows artifacts via [[osslsigncode]] (OpenSSL/cURL; no Windows/`signtool`; PKCS#11 + RFC 3161; page hash / nested signatures / catalog creation) (source: wiki/sources/descriptions/mtrojnar__osslsigncode.md); Windows Forms GUI wrapper for Microsoft `signtool` via [[signtoolgui]] (cert store / PFX / Azure Trusted Signing; batch sign, validation, PowerShell CI/CD export) (source: wiki/sources/descriptions/michaelmsonne__SignToolGUI.md); low-level PE Authenticode digest computation via [[pedigest]] (hash-exclusion over checksum + security directory; BCrypt SHA-*; `WIN_CERTIFICATE` parse; kernel `ksecdd` + usermode `bcrypt`) (source: wiki/sources/descriptions/mihaly044__pedigest.md); in-kernel PE Authenticode certificate metadata extraction via [[driver-soul-extraction]] (gmh5225; Lib-SoulExtraction; PKCS#7/ASN.1/X.509 parse in kernel; signer subject + validity window; Extracting cert information) (source: wiki/sources/descriptions/gmh5225__Driver-SoulExtraction.md); Partner Center WHQL/Attestation submission automation via [[sdcm]] (Microsoft CLI; REST API product submissions, signed driver download, Windows Update shipping labels) (source: wiki/sources/descriptions/microsoft__SDCM.md); CET/shadow-stack research such as [[cet-research]] under `Windows Security Features` (source: wiki/sources/descriptions/yardenshafir__cet-research.md); Windows 10 kernel CET support research such as [[cet-win10]] (gmh5225; shadow stack + indirect branch tracking; forward/backward-edge CFI) (source: wiki/sources/descriptions/gmh5225__CET-win10.md); Control Flow Guard (CFG) bitmap inconsistency shellcode detection such as [[cfg-find-hidden-shellcode]] (C; CFG-valid executable pages outside module `.text`; EDR/AC research) (source: wiki/sources/descriptions/jdu2600__CFG-FindHiddenShellcode.md); WinDbg CFG map inspection via [[cfgdump]] (JKornev; C++ extension; print CFG maps, query ranges, list protected regions; exploit dev + hardening validation) (source: wiki/sources/descriptions/JKornev__cfgdump.md); kernel-mode shadow-stack / CET analysis (KVAS init, exception paths, [[patchguard]] interaction) such as [[windows-kernel-shadow-stack]] (source: wiki/sources/descriptions/synacktiv__windows_kernel_shadow_stack.md); Windows PoCs for querying CET shadow-stack contents and mismatch detection such as [[query-shadow-stack]] (gmh5225; return-address integrity research) (source: wiki/sources/descriptions/gmh5225__QueryShadowStack.md); HVCI/kCET-aware bugcheck (BSOD) suppression PoC such as [[bugcheck-suppressor]] (XaFF-XaFF; data-only HAL dispatch hook + bugcheck-callback interception + SEH `RtlUnwindEx` recovery; CET-compatible assembly stubs; kernel exception research) (source: wiki/sources/descriptions/XaFF-XaFF__BugcheckSuppressor.md); UEFI-stage no-BSOD PoC such as [[nomore-bugcheck-reloaded]] (NSG650; EFI loader patches kernel during boot—export lookup, pattern search, low-level memory overwrite; moves bugcheck interception from runtime driver to firmware stage; early boot patching research) (source: wiki/sources/descriptions/NSG650__NoMoreBugCheckReloaded.md); runtime **`KeBugCheckEx`** patch driver such as [[nomore-bugcheck]] (NSG650; direct code patch + restoration logic suppresses standard BSOD handling; kernel-hooking experiment demonstrating safety-mechanism bypass risks) (source: wiki/sources/descriptions/NSG650__NoMoreBugCheck.md); BSOD appearance/behavior hack such as [[bugcheckhack]] (NSG650; driver + user-mode utility; service workflow kernel load, offset resolution, bugcheck-routine patching; desktop controller; crash-mechanism research / kernel patching demo) (source: wiki/sources/descriptions/NSG650__BugCheckHack.md); BSOD-phase RISC-V Linux emulator such as [[bugcheck2linux]] (NSG650; kernel driver boots mini-rv32ima inside bugcheck screen; BOOTVID framebuffer + embedded device tree/boot image; kernel-mode embedded emulation research) (source: wiki/sources/descriptions/NSG650__BugCheck2Linux.md); BSOD Bad Apple framebuffer hack such as [[bad-bugcheck]] (NSG650; hooks `KeBugCheckEx`; maps display framebuffer instead of legacy BOOTVID VGA; stb_image frame draw; crash-screen rendering / bugcheck hooking research) (source: wiki/sources/descriptions/NSG650__Bad-Bugcheck.md); legacy BOOTVID animated BSOD PoC such as [[bad-bugcheck-old]] (NSG650; kernel driver; Bootvid `VidBitBlt` VGA-style frame playback on forced crash screen; triggers bugcheck after animation; early BSOD graphics research) (source: wiki/sources/descriptions/NSG650__Bad-BugCheck-Old.md); compact BOOTVID bitmap crash-screen PoC such as [[kmdfmandelcheck]] (AnalogFeelings; KMDF kernel driver; renders bitmap on BSOD via modified BOOTVID interface; minimal crash-time display / boot-video research) (source: wiki/sources/descriptions/AnalogFeelings__KmdfMandelcheck.md); TPM 2.0 stack integrity checks such as [[detect-tpm-spoofing]] (KMDF; compare IOCTL `TPM2_ReadPublic` to `TPM.sys` cached buffers to catch EK/public-key forgery) (source: wiki/sources/descriptions/weak1337__DetectTpmSpoofing.md); offensive TPM identifier spoof via hooked TPM request paths such as [[tpm-spoofer]] (KM hook + UM EK/serial checker; SamuelTulach EK-interception PoC) (source: wiki/sources/descriptions/SamuelTulach__tpm-spoofer.md) (source: wiki/sources/descriptions/s0ngidong3__TPM-SPOOFER.md); MMIO-path TPM 2.0 public Endorsement Key reads that bypass OS hooks such as [[tpm-mmio]] (source: wiki/sources/descriptions/synctop__tpm-mmio.md); DSE-bypass / unsigned-load controllers such as [[kvc]] (`g_CiOptions` via signed Microsoft driver, `skci.dll` / `SeCiCallbacks` loaders, PP/PPL→LSASS on HVCI/VBS) (source: wiki/sources/descriptions/wesmar__kvc.md); Win11 25H2 boot-time DSE / CI research kits such as [[kernel-research-kit]] (native-subsystem `SeCiCallbacks` patch, manual map / IRP hijack / BYOVD load paths, anti-loop dual-path) (source: wiki/sources/descriptions/wesmar__KernelResearchKit.md); Secure Boot / boot-manager + CI.dll early-phase DSE/HVCI bypass such as [[bootbypass]] (`subsystem:native`; smart `SeCiCallbacks` patching; independent Memory Integrity management) (source: wiki/sources/descriptions/wesmar__BootBypass.md); bootExecute-path EDR bypass research such as [[bootexecute-edr]] (runs before Windows services; cheat / hide lane) (source: wiki/sources/descriptions/rad9800__BootExecuteEDR.md); HVCI `HvciDisallowedImages` custom-blocklist CLIs such as [[solemn]] (automate driver disallow entries under Memory Integrity) (source: wiki/sources/descriptions/unkvolism__Solemn.md); Microsoft Recommended Driver Block Rules reference such as [[msft-driverblocklist]] (community mirror for AC / black-signature defensive research) (source: wiki/sources/descriptions/jsecurity101__MSFT_DriverBlockList.md); WDAC CI policy blocklist XML datasets such as [[code-integrity-driverblocklist]] (Harvester57; large deny rules by hash and driver identity incl. anti-cheat kernel modules; configuration data for WDAC/policy tooling; defensive hardening + attack-surface reduction) (source: wiki/sources/descriptions/Harvester57__CodeIntegrity-DriverBlocklist.md); black-signature kernel driver development such as [[black-signature-driver]] (gmh5225; driver dev + networking; Anti Cheat → Black Signature research) (source: wiki/sources/descriptions/gmh5225__BlackSignatureDriver.md); leaked-cert + clock-rollback DSE research such as [[pastdse]] (VeriSign material; BlackBone PE load/reloc; date restore after sign) (source: wiki/sources/descriptions/utoni__PastDSE.md); CI.dll hook / `g_CiEnabled` patch PoCs such as [[dse-hook]] (gmh5225; signature verification bypass for unsigned driver load; kernel DSE research) (source: wiki/sources/descriptions/gmh5225__dse_hook.md); ci.dll API validation demos such as [[ci-dll-demo]] (Ido-Moshe-Github; kernel driver; process-creation notify hook; `CiValidateFileObject` / `CiCheckSignedFile`; Authenticode certificate extraction; x86/x64; Windows Code Integrity kernel-mode research) (source: wiki/sources/descriptions/Ido-Moshe-Github__CiDllDemo.md); direct `ci.dll!g_CiOptions` patch PoCs such as [[dse-patcher-2]] (gmh5225; disable kernel code-integrity validation for unsigned driver load; DSE research) (source: wiki/sources/descriptions/gmh5225__Dse-Patcher-2.md); kernel validation-chain patch PoCs such as [[disabledse]] (gmh5225; patch `SeValidateImageHeader` path via `MiValidateSectionCreate` / `MiValidateSectionSigningPolicy`; unsigned driver load; DSE research) (source: wiki/sources/descriptions/gmh5225__DisableDSE.md); signed-driver DSE dodge PoCs such as [[dsedodge-signed-kernel-driver]] (gmh5225; legitimately signed driver certificate loads kernel code without DSE validation failure; PTT-based DSE defeat research) (source: wiki/sources/descriptions/gmh5225__DSEDodge-Signed-Kernel-Driver.md); CPU-Z [[byovd]] DSE-disable utility such as [[cpuc-dsefix]] (SamLarenN; C++; vulnerable CPU-Z driver → kernel patch of `g_CiEnable`/`g_CiOptions`; pattern scan + unsigned driver load helpers; PatchGuard crash risk; kernel DSE research; cheat / CPU-Z) (source: wiki/sources/descriptions/SamLarenN__CPUZ-DSEFix.md); runtime TestSigning toggle PoCs such as [[ts-fucker]] (gmh5225; Dell **`dbutil_2_3.sys`** BYOVD kernel R/W → live-patch test-signing without reboot; symbol download for build-specific offsets; expects driver pre-loaded) (source: wiki/sources/descriptions/gmh5225__TS-Fucker.md); HVCI bypass PoCs such as [[zero-hvci]] (gmh5225; policy edge cases + [[byovd]] primitives → unsigned kernel code under Memory Integrity; VBS limitation research) (source: wiki/sources/descriptions/gmh5225__ZeroHVCI.md); VBS/HVCI-era user-mode kernel invocation libraries such as [[kernel-forge]] (Cr4sh; C++; signed-driver-wrapper kernel-memory primitives + higher-level kernel routine calls; kernel-to-user DLL injection example; advanced kernel security / exploit-prototyping under Memory Integrity; README [Hijack ROP]) (source: wiki/sources/descriptions/Cr4sh__KernelForge.md); VBS enclave abuse PoCs such as [[fake-enclave]] (gmh5225; C/C++; abuses Enclave isolation; Some Tricks / Windows Ring0; VBS trust-feature limitation research) (source: wiki/sources/descriptions/gmh5225__FakeEnclave.md); Hyper-V / VBS teardown guides such as [[disabling-hyper-v]] (gmh5225; Win10; Device Guard + Credential Guard + hardware readiness tool → disable HVCI and virtualization-based security for full Hyper-V removal; cheat / guide) (source: wiki/sources/descriptions/gmh5225__Disabling-Hyper-V.md); leaked-cert signing tooling such as [[magic-signer]] (admin; temporary TLS/HTTPS breakage while signing) (source: wiki/sources/descriptions/namazso__MagicSigner.md); expired-cert `signtool` sideload + in-process API patch tooling such as [[sign-expired]] (XmlLite.dll hijack; `CertVerifyTimeValidity` / `GetSystemTimeAsFileTime` zeroing via `WriteProcessMemory`; no system clock rollback) (source: wiki/sources/descriptions/mathisvickie__sign-expired.md); Detours `signtool` import-hook tooling such as [[fuck-cert-verify-time-validity]] (LordPE import; `CertVerifyTimeValidity` always succeeds; `-fuckyear` controls `GetLocalTime`; Sign Leaked Cert) (source: wiki/sources/descriptions/hzqst__FuckCertVerifyTimeValidity.md); Detours hook DLL for code-signing utilities such as [[hooksigntool]] (Jemmy1228; certificate validity + timestamp API interception; custom timestamp endpoints and signing-time control via config/CLI; Sign Leaked Cert research) (source: wiki/sources/descriptions/Jemmy1228__HookSigntool.md); leaked/expired-cert `signtool` tooling such as [[signtoolex]] (Sign Leaked Cert; expired/leaked Authenticode certs; no Authenticode timestamp spoofing) (source: wiki/sources/descriptions/hackerhouse-opensource__SignToolEx.md); CVE-2020-0601 CryptoAPI ECC root-spoof PoC such as [[chainoffools]] (Python + OpenSSL; rogue P-384 CA matching trusted root public key; gmh5225 fork of Kudelski ChainOfFools/CurveBall) (source: wiki/sources/descriptions/gmh5225__chainoffools.md); LSA credential forensics from live LSASS / `lsass.dmp` via [[kvcforensic]] (MSV/WDigest/Kerberos/CredMan/DPAPI; Win11 24H2–26H1) (source: wiki/sources/descriptions/wesmar__KvcForensic.md); undocumented DPAPI RPC decryption PoCs such as [[custom-dpapi]] (EvilBytecode; C++; `NdrClientCall3` → lsass `protected_storage` RPC; bypasses `CryptUnprotectData`; dpapi.dll internals RE; credential protection / RPC attack-surface research) (source: wiki/sources/descriptions/EvilBytecode__CustomDpapi.md); Defender real-time / Tamper Protection control via kernel privilege-escalation CLIs such as [[windefctl]] (Win11 26H1; UAC/GUI bypass, stealth execution) (source: wiki/sources/descriptions/wesmar__WinDefCtl.md); user-mode C# GUI toggles via registry/service config such as [[defender-control]] (real-time / Tamper Protection / sample submission) (source: wiki/sources/descriptions/qtkite__defender-control.md); integrated UAC bypass + SYSTEM escalation tooling such as [[disable-windows-defender-]] (gmh5225; COM-based UAC bypass + privilege-token manipulation → real-time + Tamper Protection disable) (source: wiki/sources/descriptions/gmh5225__Disable-Windows-Defender-.md); WDAC CI policy authoring/deployment via PowerShell such as [[wdactools]] (base/supplemental policies, UMCI/WHQL/audit/managed-installer options, CIPolicyParser, CiTool.exe deploy, p7b decrypt) (source: wiki/sources/descriptions/mattifestation__WDACTools.md) - **[[byovd]]:** signed vulnerable drivers → kernel R/W → unsigned load / blind AC; defensive CVE study notes such as [[kernel-cve-analysis]] (thexin7; root-cause write-ups, IOCTL/load/token/crash telemetry mapping, Sigma sketches, hardening checklists; `cng.sys`/`afd.sys` pool LPE and `appid.sys` BYOVD-style pointer overwrite; lab validation via Driver Verifier/ETW—not published exploit binaries) complement offensive guides in the same lane (source: wiki/sources/descriptions/thexin7__kernel-cve-analysis.md); canonical LOLdriver catalog [[loldrivers]] (magicsword-io; YAML metadata, YARA enrichment, HVCI tracking, validation tooling) (source: wiki/sources/descriptions/magicsword-io__LOLDrivers.md); Microsoft-acknowledged vulnerable-driver hash inventory [[ms-vulnerable-driver-list]] (gmh5225; blocklist-derived hash list; signed drivers with known IOCTL-exploitable flaws for BYOVD research) (source: wiki/sources/descriptions/gmh5225__MS-Vulnerable-Driver-List.md); lightweight filesystem triage CLI [[vulnerable-driver-scanner]] (Xxmmy; C++; scans directories for vulnerable Windows drivers in common system paths; BYOVD exposure triage for bypass research, IR, defensive audits) (source: wiki/sources/descriptions/Xxmmy__vulnerable-driver-scanner.md); PE-import triage CLI [[vulnerable-driverscanner]] (Sentient111; folder scan; flags driver PEs with indicative kernel API imports; preliminary attack-surface assessment—not full behavioral analysis) (source: wiki/sources/descriptions/Sentient111__VulnerableDriverScanner.md); read-only endpoint driver risk scanner [[driver-risk-scout]] (Systemhaus-Schulz; PowerShell + Python collector; LOLDrivers/MS blocklist/BYOVD profile correlation; PE/YARA scoring; Sysmon/Code Integrity + HVCI/VBS/WDAC posture; CSV/JSON/HTML/Wazuh NDJSON; defender/IR/game-security BYOVD hunting without host modification) (source: wiki/sources/descriptions/Systemhaus-Schulz__DriverRiskScout.md); unprivileged Go LOLdriver scanner [[loldriverscan]] (FourCoreLabs; public threat feed; local hash/metadata compare; verbose + JSON export; defensive auditing and AC environment checks) (source: wiki/sources/descriptions/FourCoreLabs__LolDriverScan.md); educational **`eneio64.sys`** physmem exploit PoC such as [[eneio64-driver-exploit]] (Xacone; C++; signed-driver physical memory R/W → VA translation → token-theft LPE; kernel exploit training) (source: wiki/sources/descriptions/Xacone__Eneio64-Driver-Exploit.md); ThrottleStop **`ThrottleStop.sys`** CVE-2025-7771 PoC such as [[throttlestop-poc]] (U65535F; C; IOCTL physmem R/W + I/O port R/W from user mode; VA translation + basic EPROCESS checks; vulnerable-driver / AC threat-modeling research) (source: wiki/sources/descriptions/U65535F__ThrottleStopPoC.md); ViGEmBus **`ViGEmBus.sys`** virtual gamepad driver IOCTL/access-control PoC such as [[vigembus-driver-exploitation]] (CyberSecurityUP; C++; insecure IOCTL handling + access-control flaws; multiple PoCs for privilege escalation or system instability; RE artifacts; gaming peripheral driver hardening research) (source: wiki/sources/descriptions/CyberSecurityUP__ViGEmBus-Driver-Exploitation.md); educational kernel-exploit guides such as [[windows-kernel-exploits]] (Cheat Vulnerable Driver lane) and modular exploitation frameworks such as [[trinity]] (cpz; C/C++; chains driver vulns, memory corruption, and priv-esc primitives into a pipeline → arbitrary kernel code execution; README fully disables & removes Windows Defender) (source: wiki/sources/descriptions/cpz__trinity.md) and hands-on vulnerable-driver labs such as [[hacksysextremevulnerabledriver]] (HackSys Team guide; kernel exploitation training) (source: wiki/sources/descriptions/hacksysteam__HackSysExtremeVulnerableDriver.md) and [[vulnerablekernel-driver]] (gmh5225; **`MsIo64.sys`**; IOCTL demos for arbitrary R/W, overflow, UAF, race conditions; kernel exploitation training) (source: wiki/sources/descriptions/gmh5225__VulnerableKernel_Driver.md); physmem-capable vulnerable-driver inventories such as [[physmem-drivers]] (namazso; list only, no PoC) (source: wiki/sources/descriptions/namazso__physmem_drivers.md); categorized third-party `.sys` binary corpus [[drivers-and-shit]] (alfarom256; OEM/utility/security drivers; vulnerable-driver research reference—binaries only, no PoC) (source: wiki/sources/descriptions/alfarom256__drivers_and_shit.md); curated signed vulnerable-driver binary collection [[vulnerable-drivers]] (KeServiceDescriptorTable; dozens of vendor `.sys` binaries with exploitable IOCTL interfaces, memory-access primitives, or other weaknesses; BYOVD cataloging and exploitation-surface analysis) (source: wiki/sources/descriptions/KeServiceDescriptorTable__vulnerable-drivers.md); multi-vendor `.sys` sample corpus [[drivers-binaries]] (CaledoniaProject; compiled vendor driver binaries + CVE/report/exploit writeup links; detection-rule, threat-hunting, and signed-driver-abuse defensive testing; defender-focused kernel attack-surface research; README Vulnerable Driver List) (source: wiki/sources/descriptions/CaledoniaProject__drivers-binaries.md); single-driver **`cormem.sys`** distribution [[cormem-sys-vulnerable-driver]] (KeServiceDescriptorTable; memory R/W primitives for kernel-level BYOVD research) (source: wiki/sources/descriptions/KeServiceDescriptorTable__cormem.sys-vulnerable-driver.md); AV/EDR-evasion research such as [[ven0m-ransomware]] via `iMFForceDelete.sys` (IObit Malware Fighter), LPE PoC [[cve-2025-26125]] (ZeroMemoryEx; CVE-2025-26125; MSI-based file/folder deletion abuse → SYSTEM) (source: wiki/sources/descriptions/ZeroMemoryEx__CVE-2025-26125.md), IObitUnlocker file-manipulation PoC [[cve-2020-14974]] (gmh5225; CVE-2020-14974; **`IObitUnlocker.sys`** 1.1.2; IOCTL unlock/delete/rename/copy/move in-use files from low privilege) (source: wiki/sources/descriptions/gmh5225__CVE-2020-14974.md), and [[av-edr-killer]] via `wsftprm.sys` IOCTL `0x22201C` (PID in first DWORD of 1036-byte buffer); Zemana anti-malware driver abuse such as [[zam64-zemina]] (`zam64.sys`; IOCTL process termination + memory access) (source: wiki/sources/descriptions/gmh5225__zam64-zemina.md) and focused AV/EDR/AC terminate tooling such as [[terminator]] (gmh5225; same **`zam64.sys`** backend; arbitrary process-termination IOCTL → kill kernel-protected security and anti-cheat processes) (source: wiki/sources/descriptions/gmh5225__Terminator.md) and Go Spyboy Terminator reproduction [[edr-xdr-av-killer]] (EvilBytecode; IOCTL PID trust-list bypass on **`zam64.sys`** → kernel EDR/XDR/AV termination; BYOVD evasion research) (source: wiki/sources/descriptions/EvilBytecode__EDR-XDR-AV-Killer.md); GMER anti-rootkit driver abuse such as [[blackout]] (gmh5225; **`gmer64.sys`** from [[loldrivers]]; BYOVD IOCTL PID kill for EDR/AV; continuous Windows Defender suppression) (source: wiki/sources/descriptions/gmh5225__Blackout.md); curated educational BYOVD lab [[entities/byovd|BYOVD Lab]] (gmh5225; multi-driver AV/EDR kill PoCs—`viragt64.sys`, TfSysMon, ksapi64, BdApiUtil, `wsftprm.sys`; Viragt64 branch documents post-publication real-world campaign overlap) (source: wiki/sources/descriptions/gmh5225__BYOVD.md); **`viragt64.sys`** process-kill tooling such as [[process-killer-byovd]] (gmh5225; BYOVD load → kernel access → forceful termination of protected AC/EDR/AV processes) (source: wiki/sources/descriptions/gmh5225__ProcessKiller-BYOVD.md); **`NSecKrnl.sys`** process-termination PoC such as [[nsecsoft-byovd]] (ANYLNK; vulnerable third-party driver → privileged target-PID actions; real-world abuse framing + assigned CVE; endpoint hardening research; README `[NSecKrnl.sys]`) (source: wiki/sources/descriptions/ANYLNK__NSecSoftBYOVD.md); malware-style multi-stage PoC such as [[urek-mazino-malware]] (CyberSecurityUP; C++; **`viragt64.sys`** BYOVD IOCTL security-process kill → WinINet download + temp execute + shellcode loader; BYOVD threat simulation / IR / endpoint tampering research; README `[viragt64.sys]`) (source: wiki/sources/descriptions/CyberSecurityUP__UrekMazino-Malware.md); **`PoisonX.sys`** Cobalt Strike BOF collection such as [[poison-killer-bof]] (Muz1K1zuM; MinGW C BOFs + Python helper; process kill, driver load/unload, kernel file deletion; red-team BYOVD BOF payloads; README `[PoisonX.sys]`) (source: wiki/sources/descriptions/Muz1K1zuM__PoisonKiller_bof.md); kernel [[killer]] (gmh5225; driver-backed forceful termination via kernel process-structure manipulation; protected AC/EDR/AV targets; reportedly not HVCI-blocklisted / not LOLdriver at publication) (source: wiki/sources/descriptions/gmh5225__Killer.md); RE lab [[killer-exercice]] (gmh5225; handle-table manipulation, APC injection, direct `EPROCESS` modification; valid BYOVD killer reportedly not HVCI-blocklisted / not LOLBIN at publication) (source: wiki/sources/descriptions/gmh5225__Killer-Exercice.md); **`RTCore64.sys`** PPL-strip tooling such as [[pplkiller]] (gmh5225; BYOVD kernel R/W → patch `EPROCESS` protection level; downgrade PPL antimalware for debug/terminate; PPL bypass research) (source: wiki/sources/descriptions/gmh5225__PPLKiller.md); PPL lab spawn loader such as [[createprocessasppl]] (2x7EQ13; C++ CLI; WinTCB/Windows/Antimalware/LSA launch modes; protected-process boundary and tooling compatibility research) (source: wiki/sources/descriptions/2x7EQ13__CreateProcessAsPPL.md); Samsung S4 vulnerable-driver abuse such as [[s4killer]] (`probmon.sys`; crafted IOCTL → phys/virt kernel R/W; unsigned load / AC bypass research) (source: wiki/sources/descriptions/gmh5225__s4killer.md); Razer peripheral driver abuse such as [[razer-rzctl]] (`rzctl.sys`; privileged I/O → kernel mouse/keyboard simulation or kernel memory via vulnerable IOCTLs; BYOVD + ring-0 input research) (source: wiki/sources/descriptions/gmh5225__razer-rzctl.md); Razer Synapse **`rzpnk.sys`** PoC [[cve-2017-9769]] (gmh5225; CVE-2017-9769; crafted IOCTL → ZwOpenProcess; arbitrary process handle from low privilege; v2.20.15.1104) (source: wiki/sources/descriptions/gmh5225__CVE-2017-9769.md); Qualcomm QCI0701 ACPI driver abuse such as [[qiomem]] (`QIOMem.sys`; virtual software device → IOCTL physical memory R/W; BYOVD physmem research) (source: wiki/sources/descriptions/gmh5225__qiomem.md); OEM BootRepair terminate killers such as [[phantomkiller]] (`BootRepair.sys` IOCTL `0x222014` → `ZwTerminateProcess`; PPL AV/EDR); FortiClient anti-exploit minifilter abuse such as [[forti-research]] (mein-0; **`fortimon3_74.sys`**; Filter Manager port → unauthenticated 8-byte kill message; kernel terminate incl. PPL Defender/lsass; Fortinet-signed BYOVD; anti-exploit product security research) (source: wiki/sources/descriptions/mein-0__forti-research.md); WatchDog Anti-Malware terminate PoCs such as [[watchdog-killer]] (`amsdk.sys`/`wamsdk.sys`; `IOCTL_REGISTER_PROCESS` `0x80002010` + `IOCTL_TERMINATE_PROCESS` `0x80002048`; EDR/AV killer; Silver Fox tradecraft; blocklist gap at publication) (source: wiki/sources/descriptions/gmh5225__WatchDogKiller.md); AC-driver IRP abuse such as [[xign-poc-april-2026]] (`xhunter64.sys` / XIGNCODE3: `IRP_MJ_WRITE` → phys R/W, kernel address leak, process kill); expanded XIGNCODE3 suite [[axhunter]] (BlackSnufkin; Rust; `xhunter1.sys`/`xhunter2.sys` CVE-2026-15430; WriteFile frames → PPL-bypass handles, arbitrary UM process memory R/W, LSA credential extraction, protected-process handle close, SYSTEM shell via winlogon) (source: wiki/sources/descriptions/BlackSnufkin__AxHunter.md); Defender-driver LSASS credential dumps such as [[kslkatz]] (`KslD.sys` → WDigest/LSA secrets past PPL/AV) and [[ksldump]] (andreisss; legacy on-disk **`KslD.sys`**; IOCTL `0x222044` + `MmCopyMemory` read + KASLR CR leak; no external driver load; PPL LSASS dump / vendor BYOVD research) (source: wiki/sources/descriptions/andreisss__KslDump.md); OEM-driver LPE such as [[lenovo-cve-2025-8061]] (`LnvMSRIO.sys` / CVE-2025-8061 IOCTL → kernel R/W / SYSTEM shell); Agere Modem `METHOD_NEITHER` IOCTL abuse such as [[cve-2025-24990-poc]] (`ltmdm64.sys` / CVE-2025-24990: `IOCTL_GET_VERSION` 4-byte write + null-deref fixup → kernel R/W; IoRing LPE variant) (source: wiki/sources/descriptions/moiz-2x__CVE-2025-24990_POC.md); classic signed-utility abuse such as [[cpuz]] (CPU-Z; XP–Win10 1607); BitLocker **`PdFwKrnl.sys`** IOCTL abuse such as [[pdfwkrnl-exploit]] (unsigned kernel code load/exec → arbitrary kernel code execution) (source: wiki/sources/descriptions/gmh5225__pdfwkrnl-exploit.md); **`ampa.sys`** IOCTL abuse such as [[ampa-sys-exp]] (gmh5225; C/C++ automated exploit; insecure IOCTL → kernel R/W or code execution; unsigned load / LPE / AC bypass) (source: wiki/sources/descriptions/gmh5225__ampa.sys-exp.md); AMD Ryzen Master v17 kernel driver abuse such as [[amd-ryzen-master-driver-v17-exploit]] (gmh5225; IOCTL → unprivileged physical memory R/W; BYOVD kernel exploitation / driver mapping / AC bypass) (source: wiki/sources/descriptions/gmh5225__amd-ryzen-master-driver-v17-exploit.md); Rentdrv2 **`Rentdrv2.sys`** PoC such as [[badrentdrv2]] (gmh5225; insecure IOCTL → arbitrary physmem R/W; driver map / kernel patch / AC bypass; Rentdrv2 BYOVD research) (source: wiki/sources/descriptions/gmh5225__BadRentdrv2.md); HITCON 2023 **`AMDCpuProfiler.sys`** demo such as [[hitcon-2023-demo-cve-2023-20562]] (gmh5225; CVE-2023-20562; AMD driver LPE / arbitrary kernel code execution; conference PoC) (source: wiki/sources/descriptions/gmh5225__HITCON-2023-Demo-CVE-2023-20562.md); multi-exploit Windows kernel driver collection such as [[exploits]] (Bad-Jubies; AMD uProf **`AmdPowerProfiler.sys`** arbitrary file write CVE-2025-61969 + kernel write CVE-2026-0466; ASIO64 driver exploitation; MS-BKRP padding-oracle decryption; cheat / `[AmdPowerProfiler.sys]`) (source: wiki/sources/descriptions/Bad-Jubies__Exploits.md); CYBERSEC 2023 Taiwan **`RTCore64.sys`** BYOVD demo such as [[cybersec2023-byovd-demo]] (gmh5225; DSE flag nullification → unsigned malicious driver load; disables 360 Total Security ObRegisterCallbacks + notify callbacks → arbitrary process manipulation; conference PoC) (source: wiki/sources/descriptions/gmh5225__CYBERSEC2023-BYOVD-Demo.md); NVIDIA kernel-driver physmem library such as [[nvdrv]] (gmh5225; C++ IOCTL wrapper for **`nvoclock`/`nvlddmkm`** → user-mode physical memory R/W; BYOVD primitive for driver map / kernel patch / AC bypass; README **`nvaudio.sys`**) (source: wiki/sources/descriptions/gmh5225__NVDrv.md); Lenovo **`LenovoDiagnosticsDriver.sys`** arbitrary kernel exec such as [[lenovo-exec]] (gmh5225; insecure IOCTL → custom kernel code; user→kernel BYOVD chain) (source: wiki/sources/descriptions/gmh5225__lenovo_exec.md); Qihoo 360 handle-donor abuse such as [[dsark64]] (`DsArk64.sys`: suspended installer + shellcode open `\\.\DsArk`, `DuplicateHandle` → ring-0 kill + kernel R/W); WFP network-blinding such as [[360wfp-exploit]] (`360netmon_x64.sys_wfp` → block EDR/XDR network connections) (source: wiki/sources/descriptions/kyxiaxiang__360WFP_Exploit.md); miHoYo AC-driver IOCTL abuse such as [[mhyprot2]] (gmh5225; kernel R/W + process termination via **`mhyprot2.sys`**), [[mhyprot2drvcontrol]] (gmh5225; C++ control library for the same driver's IOCTL surface — process R/W, module enum, process kill), [[mhydeath]] (gmh5225; BYOVD arbitrary kernel ops via the same signed AC driver), and CLI PoC [[evil-mhyprot-cli]] (Genshin Impact → unprivileged kernel/user R/W; gmh5225/kkent030315 forks; `mhyprot::init` service front end); CVE tracking [[cve-2020-36603]] (gmh5225; **`mhyprot2.sys`** 1.0.0.0 unprivileged-call restriction failure → SYSTEM LPE) (source: wiki/sources/descriptions/gmh5225__mhyprot2.md) (source: wiki/sources/descriptions/gmh5225__Mhyprot2DrvControl.md) (source: wiki/sources/descriptions/gmh5225__mhydeath.md) (source: wiki/sources/descriptions/gmh5225__evil-mhyprot-cli.md) (source: wiki/sources/descriptions/kkent030315__evil-mhyprot-cli.md) (source: wiki/sources/descriptions/gmh5225__CVE-2020-36603.md); downstream title-internal integration such as [[paladins-internal-cheat]] (gmh5225; Paladins internal hack refactored to optional **Mhyprot** driver backend; borderless-window overlay; cheat / game:paladins) (source: wiki/sources/descriptions/gmh5225__Paladins-internal-Cheat.md); **`msIo64.sys`** physmem-mapping research such as [[ms-io-exploit]] (anycall referenced for full client/driver implementation) (source: wiki/sources/descriptions/kkent030315__MsIoExploit.md); Gigabyte **`gdrv64.sys`/`gdrv.sys`** loader tooling such as [[gdrv-loader]] (gmh5225; arbitrary R/W IOCTL → manual map unsigned PE; DSE bypass via BYOVD), [[gdrv-loader-v2]] (C/C++; cheat / vulnerable-driver driver development), updated loader [[gdrv-loader-updated]] (1337kenzo; C/C++; Win10/11; CLI load/unload; kernel security lab experiments; README `[gdrv.sys Win11]`), PoC exploit toolkit [[gdrv-sys-exploit]] (AmitMoshel1; C++ Visual Studio; arbitrary-write and shellcode-oriented `gdrv.sys` examples on modern Windows/Win11; educational BYOVD kernel exploitation research), and access-primitive library [[gdriver-lib]] (gmh5225; C++ wrapper for physmem R/W, physical mapping, and kernel ops via gdrv IOCTLs); CVE-2018-19320 DSE-bypass PoC [[cve-2018-19320]] (gmh5225; **`gdrv.sys`** ring-0 memcpy-like IOCTL → leak/toggle **`CI!g_CiOptions`** to disable DSE); LPE variant [[cve-2018-19320-lpe]] (gmh5225; arbitrary alloc/write IOCTLs → SYSTEM escalation; Win10 x64 21H1) (source: wiki/sources/descriptions/gmh5225__gdrv-loader.md) (source: wiki/sources/descriptions/holi4m__gdrv-loader-v2.md) (source: wiki/sources/descriptions/gmh5225__gdriver-lib.md) (source: wiki/sources/descriptions/gmh5225__CVE-2018-19320.md) (source: wiki/sources/descriptions/gmh5225__CVE-2018-19320-LPE.md) (source: wiki/sources/descriptions/AmitMoshel1__gdrv_sys_exploit.md) (source: wiki/sources/descriptions/1337kenzo__gdrv-loader-updated.md); multi-backend [[byovd]] kits such as [[vdk]] (Vulnerable Driver Kit; unified interface across vulnerable signed-driver backends incl. Speedfan.sys; kernel R/W, process manipulation, driver load) (source: wiki/sources/descriptions/gmh5225__vdk.md); dedicated **`Speedfan.sys`** PoC such as [[speedfan-exploit]] (gmh5225; SpeedFan hardware-monitoring IOCTL abuse → physmem R/W for arbitrary kernel access; legacy monitoring-tool BYOVD research) (source: wiki/sources/descriptions/gmh5225__SpeedFan-Exploit.md); OpenHardwareMonitor **`OpenHardwareMonitorLib.sys`** MSR-exposure PoC such as [[openhardwaremonitor-poc]] (gmh5225; IOCTLs `0x9C402084`/`0x9C402088` → arbitrary MSR R/W from user mode; hardware-monitoring driver MSR bug research) (source: wiki/sources/descriptions/gmh5225__OpenHardwareMonitor-PoC.md); modular BYOVD primitive library [[vdm]] (backengineering; Voyager Driver Manager; C++; gdrv/cpuz/etc. backends → physmem R/W, VA translation, kernel shellcode; backend for [[kdmapper]]/[[msrexec]]/bluepill; BYOVD research) (source: wiki/sources/descriptions/backengineering__VDM.md); MSR write→kernel-exec escalation library [[msrexec]] (backengineering; C++; **`IA32_LSTAR`** overwrite redirects syscall handler entry → controlled kernel shellcode from user mode; [[vdm]]/bluepill backends for initial MSR write; MSR-based privilege-escalation research) (source: wiki/sources/descriptions/backengineering__msrexec.md); HP Hardware Diagnostics **`etdsupp.sys`** IOCTL LPE PoC such as [[hp-hardware-diagnostics-poc]] (gmh5225; HP OEM diagnostics kernel driver IOCTL abuse → elevated privileges on HP systems; BYOVD / LPE research) (source: wiki/sources/descriptions/gmh5225__HPHardwareDiagnostics-PoC.md); C/C++ kernel utility [[kur]] (gmh5225; **`echo_driver.sys`** BYOVD backend; kernel R/W, process manipulation, driver-load primitives) (source: wiki/sources/descriptions/gmh5225__kur.md); echo.ac **`echo_driver.sys`** token-theft LPE writeup such as [[echoac-poc]] (gmh5225; read-memory IOCTL → SYSTEM via `EPROCESS` token overwrite; anti-cheat-adjacent screenshare driver) (source: wiki/sources/descriptions/gmh5225__echoac-poc.md); classic **`Capcom.sys`** arbitrary kernel execution such as [[dolboeb-executor]] (gmh5225; IOCTL abuse → custom kernel shellcode or arbitrary kernel function calls from user mode) (source: wiki/sources/descriptions/gmh5225__dolboeb-executor.md); DKOM tooling such as [[capcom-dkom]] (gmh5225; IOCTL `0xAA013044` → kernel shellcode via `MmGetSystemRoutineAddress`; Direct Kernel Object Manipulation research) (source: wiki/sources/descriptions/gmh5225__CapcomDKOM.md); Cheat Engine **`dbk64.sys`** IOCTL abuse such as [[dbk64-vulnerability-driver]] (gmh5225; signed CE kernel driver for RPM/WPM → arbitrary kernel R/W via vulnerable IOCTLs; debugging-tool BYOVD research) (source: wiki/sources/descriptions/gmh5225__dbk64-vulnerability-driver.md); Dell **`dbutil_2_3.sys`** CVE-2021-21551 token-theft LPE such as [[cve-2021-21551]] (gmh5225; `\\.\DBUtil_2_3`; IOCTLs `0x9B0C1EC4`/`0x9B0C1EC8` → `PsInitialSystemProcess`/`ActiveProcessLinks` SYSTEM token overwrite; README documents physmem and contiguous-memory IOCTL surface) (source: wiki/sources/descriptions/gmh5225__CVE-2021-21551.md); reusable virtual/physical memory toolkit [[cve-2021-21551-poc]] (gmh5225; `Memory` class wraps IOCTLs `0x9B0C1EC4`/`0x9B0C1EC8`/`0x9B0C1F40`/`0x9B0C1F44`; `ntoskrnl` base, `EPROCESS`/`DirectoryTableBase`, phys reads via page tables; exploitation scaffold) (source: wiki/sources/descriptions/gmh5225__CVE-2021-21551-POC.md); Dell **`dbutil_2_3.sys`** multifunction post-exploitation console such as [[kernel-cactus]] (gmh5225; user-mode toolkit; `\\.\DBUtil_2_3` IOCTLs `0x9B0C1EC4`/`0x9B0C1EC8` → ETW disable, PPL toggle, protected-process kill, token copy, file delete, shellcode injection/thread hijack; BYOVD console beyond single-purpose [[ts-fucker]]) (source: wiki/sources/descriptions/gmh5225__Kernel-Cactus.md); educational multi-PoC BYOVD toolkit [[byovd-read-write-primitive]] (0xJs; C tools; IOCTL kernel R/W; PPL/token/ETW/callback/minifilter/DSE modification PoCs; AC/EDR hardening gap study; README `[BYOVD Read Write primitive]`) (source: wiki/sources/descriptions/0xJs__BYOVD_read_write_primitive.md); **`BdApiUtil64.sys`** EDR-kill PoC [[byovd-edrkiller]] (0xJs; C; driver-interface RE + automated deployment, security-process enumeration, repeated termination, cleanup; red-team defensive-resilience study; README `[BdApiUtil64.sys]`) (source: wiki/sources/descriptions/0xJs__BYOVD_EDRKiller.md); ASUS **`bsitf.sys`/`AsusBSItf.sys`** contiguous-pool map IOCTL abuse such as [[asus-bsitf-0-day-poc]] (gmh5225; CVE-2026-13585; IOCTL `0x222808`/`0x22280C` → usermode-mapped kernel pool + physaddr leak; admin→kernel BYOVD research) (source: wiki/sources/descriptions/gmh5225__asus-bsitf-0-day-poc.md); ASUS **`AsusBiosIoDrv64.sys`** hardware-monitoring IOCTL wrapper such as [[asusdrv]] (gmh5225; motherboard utility driver → physical memory R/W; BYOVD kernel-exploitation research) (source: wiki/sources/descriptions/gmh5225__AsusDrv.md); ASUS **`AsIO3.sys`** LPE PoC such as [[asio-exploit]] (gmh5225; native-syscall shellcode → `\Device\Asusgio3`; MSR IOCTLs + **`ASIO_ADDPID`** parent-PID trust bypass; authorization-model abuse) (source: wiki/sources/descriptions/gmh5225__AsIO-Exploit.md); ASUS **`asromgdrv.sys`** IOCTL wrapper such as [[windows-10-22h2-vulnerable-driver-communication]] (gmh5225; `\\.\AsrOmgDrv` + `DeviceIoControl`; contiguous kernel memory alloc/free + control-register R/W; Win10 22H2 / Win11; reversed BYOVD interface study) (source: wiki/sources/descriptions/gmh5225__Windows-10-22H2-Vulnerable-driver-communication.md); multi-driver exploit collection such as [[win-driver-exp]] (gmh5225; multiple vulnerable signed-driver IOCTL PoCs incl. **`AsUpIO64.sys`** / CVE-2024-33218 → kernel R/W, code exec, process manipulation) (source: wiki/sources/descriptions/gmh5225__Win-Driver-EXP.md) (source: wiki/sources/descriptions/xct__windows-kernel-exploits.md) (source: wiki/sources/descriptions/xM0kht4r__VEN0m-Ransomware.md) (source: wiki/sources/descriptions/xM0kht4r__AV-EDR-Killer.md) (source: wiki/sources/descriptions/redteamfortress__PhantomKiller.md) (source: wiki/sources/descriptions/waryas__xign_poc_april_2026.md) (source: wiki/sources/descriptions/vergamota__KslKatz.md) (source: wiki/sources/descriptions/symeonp__Lenovo-CVE-2025-8061.md) (source: wiki/sources/descriptions/shareef12__cpuz.md) (source: wiki/sources/descriptions/sai2fast__DsArk64.md) - **Trusted-process mappers:** extend a high-trust process (e.g. lsass) and map unsigned driver code in that context to skip normal load telemetry — research ref [[lsass-extend-mapper]] (source: wiki/sources/descriptions/zorftw__lsass-extend-mapper.md); user-mode LSASS dump PoCs such as [[lsass-dump-that-lsass]] (gmh5225; `SystemHandleInformation` handle theft + fresh `DbgHelp.dll` `MiniDumpWriteDump`; hook-evasion / encrypted output; Elevating Handle lane) (source: wiki/sources/descriptions/gmh5225__LSASS-DumpThatLSASS.md); `MiniDumpWriteDump` hook PoCs such as [[minidumpwritedumppoc]] (Adepts-Of-0xCC; intercept dump buffers before disk write; optional encrypt + socket exfil; Python decrypt receiver; credential-dump pipeline tampering / detection research; Dump Memory) (source: wiki/sources/descriptions/Adepts-Of-0xCC__MiniDumpWriteDumpPoC.md); Rust handle-reuse LSASS dump PoCs such as [[dumpy]] (Kudaes; enumerate + duplicate existing LSASS handles via native object/system information APIs instead of direct OpenProcess; XOR-protected output + optional HTTP upload + decrypt mode; detection-evasion research; Elevating Handle By LSASS) (source: wiki/sources/descriptions/Kudaes__Dumpy.md); C++ user-mode LSASS handle-reuse bypass demos such as [[lsass-usermode-bypass]] (ContionMig; reuse LSASS process handles for memory access without kernel-driver load; stability-risk notes on sensitive-process interaction; game anti-cheat bypass tradeoff research; Elevating Handle By LSASS) (source: wiki/sources/descriptions/ContionMig__LSASS-Usermode-Bypass.md); Ring3 MiniDump callback research such as [[atpminidump]] (b4rtik; C/C++; aTPMiniDump callback instrumentation; memory analysis; AC / callback lane) (source: wiki/sources/descriptions/b4rtik__ATPMiniDump.md); minimal handle-hijack teaching PoCs such as [[handle-ripper]] (gmh5225; `SystemHandleInformation` scan + `PROCESS_DUP_HANDLE` + `DuplicateHandle`; stolen-handle reuse mechanics; DuplicateHandle lane) (source: wiki/sources/descriptions/gmh5225__Handle-Ripper.md); locked-file extraction via memory-mapped section handle theft such as [[idontlikefilelocks]] (EvilBytecode; C++ research collection; steal section handles, duplicate/close remote handles; read browser DBs without stopping browser; file-lock evasion / info-stealer forensics; README Dump locked files by stealing memory-mapped section handle) (source: wiki/sources/descriptions/EvilBytecode__IDontLikeFileLocks.md); named-pipe client/server memory toolkit such as [[nobastian-v2]] (ZoondEngine; C++; handle inspection + elevated-handle acquisition; remote RPM/WPM/protect/alloc/module-base over named pipes; Elevating Handle By LSASS; game-hacking / AC evasion research) (source: wiki/sources/descriptions/ZoondEngine__NoBastian_v2.md); LSASS-context kernel execution via signed **`KSecDD.sys`** IOCTL abuse such as [[kexecdd]] (gmh5225; LSASS DLL inject → `IOCTL_KSEC_IPC_SET_FUNCTION_RETURN` arbitrary kernel exec; DSE disable via `ci.dll!g_CiOptions`; original PoC; `[KSecDD.sys]` lane) (source: wiki/sources/descriptions/gmh5225__KExecDD.md) and enhanced fork [[kexecddplus]] (DSE bypass + arbitrary kernel memory manipulation) (source: wiki/sources/descriptions/gmh5225__KexecDDPlus.md) - **Known driver mappers:** catalogs of public Driver Mapper families for AC / stress-testing research — e.g. [[known-driver-mappers]] (source: wiki/sources/descriptions/stuxnet147__Known-Driver-Mappers.md); Canonical C++ manual mapper [[kdmapper]] (TheCruZ; `iqvw64e.sys` BYOVD → pool alloc, sections, imports, relocs, entry; multiple map modes; kernel bookkeeping trace cleanup; PDB/symbol helpers; broad Windows build support; DSE bypass research) (source: wiki/sources/descriptions/TheCruZ__kdmapper.md); build-pinned fork [[kdmapper-1909]] (Brattlof; Win10 1809/1903/1909; manual map + PE helpers + service management; kernel research / AC bypass study) (source: wiki/sources/descriptions/Brattlof__kdmapper-1909.md); title-integrated Apex Legends kernel-assisted externals such as [[apex-legends-driver-cheat]] (TheCruZ; BYOVD-mapped kernel driver for cross-process R/W + C++ usermode + transparent ESP/aim overlay; cheat / AC bypass research; cheat / game:apex legends) consume that mapper lane for game memory access under [[easy-anti-cheat]]. (source: wiki/sources/descriptions/TheCruZ__Apex_Legends_Driver_Cheat.md) Learner-oriented Apex ESP templates such as [[apex-legends-esp]] (RavenOfTime; kernel driver + [[kdmapper]] load path + usermode GDI overlay; Visual Studio solution for studying KM-assisted external memory-read pipelines; cheat / game:apex legends) illustrate the same mapper stack for educational shooter-ESP workflows. (source: wiki/sources/descriptions/RavenOfTime__Apex-Legends-Esp.md); minimalist C usermode BYOVD mapper [[umap]] (btbd; vulnerable signed driver physmem → kernel pool alloc, PE sections, relocs, imports, entry; avoids registry traces and standard driver-load paths; stealthy manual-map detection research; README `[EFI Manual Map]`) (source: wiki/sources/descriptions/btbd__umap.md); BTBD kernel shellcode mapper [[smap]] (C; raw position-independent shellcode → kernel pool via BYOVD arbitrary exec; no PE image / import fixup; harder PE-signature scan detection; Scatter Manual Map / shellcode payload research) (source: wiki/sources/descriptions/btbd__smap.md); Rust kdmapper library bindings such as [[kdmapper-rs]] (C/C++ + Rust; cheat / vulnerable-driver map research) (source: wiki/sources/descriptions/rmccrystal__kdmapper-rs.md); C++ Saturn manual mapper [[saturn-mapper]] (PE sections / imports / relocs; `iqvw64e.sys` BYOVD lane) (source: wiki/sources/descriptions/paysonism__saturn-mapper.md); signed-driver **section overlay** mapper [[sinmapper]] (armvirus; user-mode physmem R/W + PTE permission flip → custom kernel image in section of already-signed driver; kernel bookkeeping trace cleanup; example driver entry; stealthy manual-map / AC evasion research; README `[Manual Map In Signed Driver]`) (source: wiki/sources/descriptions/armvirus__SinMapper.md); large-page driver shellcode mapper [[lpmapper]] (VollRagm; C++; map into already-loaded large-page drivers without fresh pool alloc; registry config for large-page drivers; manual-map AC evasion research; README `[Manual Map To Large Page Driver]`) (source: wiki/sources/descriptions/VollRagm__lpmapper.md); section-mapping **candidate finder** [[driver-dll-finder]] (armvirus; enumerate `System32` / `System32\drivers` PEs; compare section size vs target image; skip loaded drivers via active services; README `[Find Driver Useless Memory]`) (source: wiki/sources/descriptions/armvirus__DriverDllFInder.md); discarded-section manual mapper [[dsmm]] (0xf1a; C kernel PoC; map custom driver into discarded section of legitimate signed driver; post-boot system thread; PatchGuard-trigger avoidance research; README `[Discarded Driver Section Manual Map]`) (source: wiki/sources/descriptions/0xf1a__DSMM.md); signed-helper-driver mapper [[cos-mapper]] (armvirus; user+kernel flow; helper driver maps unsigned payload via kernel hooks; unloaded-driver/cache trace cleanup; example entry + VS projects; README `[Signed Driver Map]`) (source: wiki/sources/descriptions/armvirus__CosMapper.md); Intel Nal **`iqvw64e.sys`** CVE-2015-2291 PoC [[cve-2015-2291]] (gmh5225; IOCTL arbitrary kernel R/W + `NtQuerySystemInformation` base leak → LPE; foundational kdmapper-family backend) (source: wiki/sources/descriptions/gmh5225__CVE-2015-2291.md); multi-provider [[byovd]] mapper [[kdu]] (Kernel Driver Utility; hfiref0x; extensible vulnerable-driver providers; DSE bypass + unsigned PE map + cleanup; Intel/ASUS/MSI/Gigabyte families) (source: wiki/sources/descriptions/hfiref0x__KDU.md); reflexive DSE-bypass loader [[capcomlib]] (gmh5225; custom PE loader; default `Capcom.sys` BYOVD backend; modular other exploitable signed drivers; unsigned driver load; DSE research) (source: wiki/sources/descriptions/gmh5225__CapcomLib.md); Lenovo **`LenovoDiagnosticsDriver.sys`** manual mapper [[lenovo-mapper]] (gmh5225; memory-access IOCTL pipeline for unsigned PE map) (source: wiki/sources/descriptions/gmh5225__lenovo_mapper.md); **`AsUpIO.sys`** manual mapper [[imxyvimapper]] (gmh5225; PE sections / imports / relocs / entry via vulnerable-driver kernel primitive) (source: wiki/sources/descriptions/gmh5225__imxyviMapper.md); **`nvaudio.sys`** manual mapper [[ucmapper]] (gmh5225; user-mode loader reuses internal **`EncodePayLoad`**; runtime-list cleanup after map) (source: wiki/sources/descriptions/gmh5225__UCMapper.md); Samsung S4 **`SignalRgbDriver.sys`** manual mapper [[s4mapper]] (gmh5225; memory-access IOCTL pipeline → pool alloc, sections, relocs, imports, entry; unsigned PE map) (source: wiki/sources/descriptions/gmh5225__S4Mapper.md); MSI Afterburner **`RTCore64.sys`** manual mapper [[rtcore64-vulnerability]] (gmh5225; RTCore64 R/W primitives + data-ptr hook dispatch; kernel routine search incl. `MmAllocateIndependentPagesEx`; unsigned PE map) (source: wiki/sources/descriptions/gmh5225__RTCore64_Vulnerability.md); BitLocker **`PdFwKrnl.sys`** DSE-bypass mapper [[pdfwkrnl-mapper]] (gmh5225; `SeValidateImageData`/header patch → unsigned driver map) (source: wiki/sources/descriptions/gmh5225__PdFwKrnlMapper.md); system-space file-section mappers such as [[map-file-in-system-space]] (gmh5225; `MmCreateSection` + `MiMapViewInSystemSpace`; map PE into kernel memory without standard file I/O; stealthy unsigned driver load research) (source: wiki/sources/descriptions/gmh5225__Map-file-in-system-space.md); custom **IoCreateDriver** load-path research such as [[iocreatedriver]] (Th3Spl; C/C++ Visual Studio + WDK; reimplements IoCreateDriver behavior; bypass standard driver-load visibility/logging; manual-map + entry-point notes; kernel experimentation / AC evasion research) (source: wiki/sources/descriptions/Th3Spl__IoCreateDriver.md); kernel function-pointer hook manual mapper [[umap-mapper]] (FarmEquipment69; C; hooks `NtConvertBetweenAuxiliaryCounterAndPerformanceCounter` dispatch for mapping requests; PE copy + import/reloc fixup + entry; pattern scan + protected memory writes; VS driver project; driver-load / AC evasion research) (source: wiki/sources/descriptions/FarmEquipment69__umap-mapper.md); session-space manual mappers such as [[driver-session-mapper]] (gmh5225; hooks internal `ntoskrnl` callback; session-memory PE map; import fix + relocs + entry; loader-metadata scrub on unload; README `[Session Driver]`) (source: wiki/sources/descriptions/gmh5225__Driver-SessionMapper.md); EAC-targeted session-driver integrity mapper PoC [[eac-mapper]] (Compiled-Code; C++; `gdrv.sys` BYOVD backend; bypasses read-only section checks when drivers are not globally mapped in EAC execution context; patching + hook placement for low-noise KM↔UM comm; AC internals / mapper attack-path research; cheat / `[gdrv.sys]`) (source: wiki/sources/descriptions/Compiled-Code__eac-mapper.md); **win32k.sys** session-driver loaders such as [[callmewin32kdriver]] (gmh5225; unsigned PE via win32k session-driver load path; anti-rootkit dump resistance + `MmCopyMemory`-detection bypass; PUBG cheat-driver lineage; README `[Load your driver like win32k.sys]`) (source: wiki/sources/descriptions/gmh5225__CallMeWin32kDriver.md); kdmapper-compatible KMDF cross-process memory IOCTL stacks such as [[anti-cheat-amateur]] (GothGirlFeet driver on hooked NUL device; MemRE UM GUI + DBVM hypercall shims; Tencent ACE evasion research) (source: wiki/sources/descriptions/not1cyyy__Anti-Cheat-Amateur.md); Win10 KDP-compatible unsigned loader [[kdp-compatible-driver-loader]] (gmh5225; `gdrv.sys` BYOVD → `SeCiCallbacks` patch via `CiInitialize`/`SeValidateImageHeader` chain) (source: wiki/sources/descriptions/gmh5225__KDP-compatible-driver-loader.md); downstream KdMapper-loaded cheat memory drivers such as [[fall-guys]] (gmh5225; Fall Guys; kernel driver communication + memory manipulation; speed/fly/physics exploits; cheat / game:fallguys) (source: wiki/sources/descriptions/gmh5225__FallGuys.md), [[flying-guys]] (gmh5225; Fall Guys; custom KM driver + ImGui overlay + zlib network manipulation; cheat / game:fallguys) (source: wiki/sources/descriptions/gmh5225__FlyingGuys.md), and expanded [[flying-guys-fully-modified]] (gmh5225; kernel driver + mapper + usermode; fly/movement hacks via KM memory access; cheat / game:fallguys) (source: wiki/sources/descriptions/gmh5225__Flying-Guys-fully-modified.md) - **Pool / Segment Heap / driver forensics:** [[kernel-pool-scanning]] covers Segment Heap paths (kLFH, VS, Segment, Large), HeapKey/LfhKey decoding, KDP Secure Pool for immutable rule tables, and why legacy `BlockSize` pool walks fail post-19H1; Big Pool snapshot/diff tooling such as [[kn-diff-pool]] (kernel driver + Go TUI; before/after new-allocation diff for leak and manual-map forensics) complements one-shot walks (source: wiki/sources/descriptions/kernullist__kn-diff-pool.md); interactive pool enumerator/dumper such as [[pooldump]] (allocation tags, sizes, owning drivers; dump specific pool contents; EAC manual-map DLL extraction research) (source: wiki/sources/descriptions/ioncodes__pooldump.md); kernel memory layout scanners such as [[memscanner]] (FaEryICE; C WDK/VS; enumerate `DRIVER_OBJECT`, LDR entries, section/file objects from live kernel regions; Win7–Win10 notes; kernel forensics / AC structure research; README Memory scanner) (source: wiki/sources/descriptions/FaEryICE__MemScanner.md); paging-structure driver-artifact scanners such as [[hygieia]] (Deputation; C/C++ WDK driver; scan paging structures for traces left by vulnerable drivers; 1 GB/2 MB/4 KB page mappings; low-level memory forensics for prior unsigned-driver activity; anti-cheat / kernel security research) (source: wiki/sources/descriptions/Deputation__hygieia.md); complementary load forensics inspect PiDDBCacheTable (historical driver hashes), MmUnloadedDrivers (recent unload ring buffer), and PoolBigPageTable for hidden manual-map footprints; registry-based execution history via AppCompat ShimCache parsers such as [[shimcacheparser]] (SYSTEM hive; paths/timestamps/flags; CSV/timeline) complements those kernel load artifacts for AC / IS forensics. (source: wiki/sources/descriptions/mandiant__ShimCacheParser.md) Bundled Windows forensics training workflows such as [[pwf]] (Personal Windows Forensics toolkit; artifact collection, timeline generation, registry analysis, IR evidence preservation; Windows Forensics Training) streamline practitioner investigations across those artifact types. (source: wiki/sources/descriptions/bluecapesecurity__PWF.md); experimental AC driver prototypes such as [[kernel-anti-cheat]] (gmh5225; big-pool inspection + PiDDBCache kdmapper/drvmap timestamp enumeration alongside other telemetry modules; research sandbox) exercise the same load-artifact lane. (source: wiki/sources/descriptions/gmh5225__Kernel_Anti-Cheat.md); [[kernel-anticheat]] (Vasieco; host-integrity scans for unsigned drivers, physmem-handle abuse, hypervisor traces, big-pool/mapper artifacts, and suspicious system threads; Visual Studio driver projects; anti-cheat research) (source: wiki/sources/descriptions/Vasieco__Kernel-Anticheat.md); post-map cleanup research such as [[revert-mapper]] (free mapping + strip pool tags / refs after unsigned-driver entry) (source: wiki/sources/descriptions/zorftw__revert-mapper.md) and [[nullmap]] (header zeroing, pool removal, reference unlink after manual map; Afd.sys; gmh5225) (source: wiki/sources/descriptions/gmh5225__nullmap.md); post-kdmapper mapped-page trace reduction PoCs such as [[map-page]] (EBalloon; C++; `MmFreePagesFromMdl` + pool cleanup; `NtUserGetObjectInformation` data-pointer comm; driver-mapping stealth / AC bypass research; README `[NtUserGetObjectInformation]`) (source: wiki/sources/descriptions/EBalloon__MapPage.md); driver backup/restore utilities such as [[ez-drv-bak]] (gmh5225; snapshot and restore Windows kernel driver images for driver-dev and AC lab baselines) (source: wiki/sources/descriptions/gmh5225__ezDrvBAK.md); legitimate orphaned AC driver/service cleanup such as [[wardsweep]] (poli0981; audit + sweep leftover kernel services/registry/filesystem after game uninstall; quarantine/rollback manifests; split-privilege broker) complements load-artifact forensics—not runtime AC disablement (source: wiki/sources/descriptions/poli0981__wardsweep.md); individual-page allocation PoCs such as [[allocating-individual-pages]] (gmh5225; `MmAllocateIndependentPagesEx`; isolated kernel pages outside standard pool paths; reduce pool-tag / BigPool scanner visibility for manual-map code; Some Tricks / MmAllocateIndependentPagesEx) (source: wiki/sources/descriptions/gmh5225__Allocating-individual-pages.md); driver trace-cleaning write-ups such as [[hlunaaa-github-io]] (CI.dll + BigPool cache; CR3 abuse with physical R/W; cheat / hide lane) (source: wiki/sources/descriptions/hLunaaa__hLunaaa.github.io.md); dedicated PiDDBCache/MmUnloadedDrivers/code-integrity hash-cache cleanup driver such as [[clear-driver-traces]] (Sentient111; C++ KM driver; version-specific offsets; driver forensics / AC artifact research; README Driver Trace Cleaner) (source: wiki/sources/descriptions/Sentient111__ClearDriverTraces.md); minimal manual-map trace-hygiene example such as [[trace-cleaner]] (BadPlayer555; C++ KM driver; clears MmUnloadedDrivers + PiDDBCacheTable; educational kernel trace cleanup; README Driver Trace Cleaner) (source: wiki/sources/descriptions/BadPlayer555__TraceCleaner.md); codecave abuse that skips new executable kernel allocations by planting shellcode in unused `.text` padding of loaded drivers such as [[kernel-codecave-poc]] (source: wiki/sources/descriptions/rogerxiii__kernel-codecave-poc.md); Hyper-V stack LPE such as [[cve-2025-21333]] uses IoRing pool spray + pipe-attribute R/W after a `vskrnlintvsp.sys` heap overflow (source: wiki/sources/descriptions/nu1lptr0__CVE-2025-21333.md); Rust compile-time IRQL-aware pool allocators such as [[irql]] (`irql_alloc` Box/Vec; NonPaged/Paged-safe KM primitives) help drivers avoid classic IRQL × pool bugs. (source: wiki/sources/descriptions/naorhaziz__irql.md) - **ETW:** provider/consumer model (manifest, TraceLogging, MOF legacy) and the PPL-gated **Microsoft-Windows-Threat-Intelligence** lane for cross-process memory access telemetry — see [[etw-threat-intelligence]] for bypass targets (`EtwEventWrite`, `EtwpEventWriteFull`, registration walks) and EPT hardening; schema discovery via [[etw-explorer]]; cross-build manifest snapshot compare/diff via [[etw-watcher]] (web UI; ETWInspector-backed) (source: wiki/sources/descriptions/jonny-jhnson__EtwWatcher.md); live ETW event and system debug-log capture via [[dbgviewex]] (emlinhax; early-stage; cheat / RE telemetry lane) (source: wiki/sources/descriptions/emlinhax__DbgViewEx.md); real-time EtwTi provider registration fluctuation monitors such as [[etwti-fluctuation-monitor]] (C; callback tamper alerts when ETW TI telemetry is blinded) (source: wiki/sources/descriptions/jdu2600__EtwTi-FluctuationMonitor.md); kernel-vs-ETW correlation monitors such as [[eyyoetwwhereyouat]] (0xjbb; EtwDriver + krabs user-mode engine; thread/image/memory events; missing ETW events flag ETW patching; injection/hollowing heuristics; CMake/MSVC) (source: wiki/sources/descriptions/0xjbb__EyYoEtwWhereYouAt.md); interactive kernel AC/forensics console such as [[hawkeye]] (hawkeye-Leo; host-native driver; `!probe`/`!etw`/`!kernel_region`; Hawkeye Lab `!analyze` scored memory-mapping/active-page/kernel-injection reports; GPL Community + paid Lab; authorized AC/kernel RE on Win10/11 x64) (source: wiki/sources/descriptions/hawkeye-Leo__hawkeye.md); user-mode EtwTi syscall activity loggers such as [[etw-syscall-monitor]] (C; SSN/params/process/thread/stacks; no kernel hook or driver) (source: wiki/sources/descriptions/jdu2600__Etw-SyscallMonitor.md); kernel-driver **PsAltSystemCallHandlers** syscall monitors such as [[callmon]] (DownWithUp; C kernel driver + user-mode GUI; per-process syscall intercept; trap frame + stack via named pipe; optional Rust driver variant; AltSystemCallHandlers / kernel telemetry / AC process-level API monitoring research) (source: wiki/sources/descriptions/DownWithUp__CallMon.md); alternate **PsAltSystemCallHandlers** mechanics research PoC such as [[win-alt-syscall-handler]] (0xcpu; C; handler registration limits, dispatch conditions, thread debug flags for callback path selection, trap-frame/process-info experiments; syscall interception stability research; README AltSystemCallHandlers) (source: wiki/sources/descriptions/0xcpu__WinAltSyscallHandler.md); kernel address leakage via ETW stack-trace consumption PoCs such as [[etwleakkernel]] (Idov31; C++; start ETW session, request provider stack data, parse events for kernel pointers; Administrator; exploitation / kernel address exposure research) (source: wiki/sources/descriptions/Idov31__EtwLeakKernel.md); ETW syscall hook/modding samples such as [[etw-syscall]] (huoji120; C/C++; Some Tricks / Windows Ring3; modding and hooking) (source: wiki/sources/descriptions/huoji120__Etw-Syscall.md); original **InfinityHook** ETW syscall hooking library such as [[infinityhook]] (everdox; C; patches ETW syscall trace callback pointer for transparent interception without SSDT or `ntoskrnl` inline hooks; PatchGuard-compatible legitimate ETW path; README `[ETW Hook]`) (source: wiki/sources/descriptions/everdox__InfinityHook.md); InfinityHook C++ wrapper samples such as [[etwhook-infinityhookclass]] (gmh5225; OO interface for ETW-backed syscall interception without SSDT modification; Some Tricks / ETW Hook Ex) (source: wiki/sources/descriptions/gmh5225__ETWHOOK-InfinityHookClass.md); evolved **InfinityHook Pro Max** framework such as [[infinityhook-promax]] (ThomasonZhao; C++ driver-oriented hook management + instruction disassembly; broader Windows version compatibility/stability; VM-tested; kernel security research / AC monitoring; README `[ETW Hook WIN11]`) (source: wiki/sources/descriptions/ThomasonZhao__InfinityHookProMax.md); **InfinityHook Latest** port such as [[infinityhook-latest]] (Oxygen1a1; C/C++ VS kernel driver; ETW + HalPrivateDispatchTable callbacks; PMC/trace RE notes; newer Windows builds; AC bypass / kernel security research; README `[ETW Hook WIN11]`) (source: wiki/sources/descriptions/Oxygen1a1__InfinityHook_latest.md); **InfinityHook Pro** modernization such as [[infinityhook-pro]] (FiYHer; C/C++ VS; InfinityHook compatibility Win7–Win11; version-specific kernel offset handling; low-level internals + extensive comments; kernel security / AC / EDR RE; README `[ETW Hook Ex]`) (source: wiki/sources/descriptions/FiYHer__InfinityHookPro.md); **InfinityHookPro Main** fork such as [[infinityhookpro-main]] (DearXiaoGui; C/C++ driver; InfinityHook derivative with physical-machine support; ETW/CKCL syscall interception, SSDT context handling, kernel pattern scanning; callback-based dispatch monitoring; Win7–Win11; AC telemetry / syscall monitoring / hook detection research; README `[ETW Hook WIN11]`) (source: wiki/sources/descriptions/DearXiaoGui__InfinityHookPro-main.md); AC-oriented kernel monitoring driver samples such as [[acdrv]] (gmh5225; process/module callbacks, memory access interception, syscall monitoring via custom driver interface; README ETW Hook tag; anti-cheat driver component research) (source: wiki/sources/descriptions/gmh5225__AcDrv.md); ThreatIntel consumers such as [[tietwagent]] (Microsoft-Windows-Threat-Intelligence injection telemetry; krabsetw/Yara; ELAM/PPL) show how those providers feed AC/EDR detection without fragile userland hooks; no-driver / non-PPL ThreatIntel consume PoCs such as [[threat-intelligence-consumer]] (Win11 24H2/25H2 + Canary; Cheat Windows kernel explorer) illustrate an alternate research path to the same provider (source: wiki/sources/descriptions/preludeorg__ThreatIntelligenceConsumer.md); broader kernel event-stream observability such as [[fibratus]] (Go; process/thread/file/registry/network/driver ETW; rule engine + Elasticsearch sinks) supports the same Windows kernel exploration / telemetry lane; Procmon-inspired GUI monitors such as [[openprocmon]] combine ETW with minifilter capture for process/file/registry/network/DLL activity; synthetic multi-provider ETW event generators such as [[bamboozledr]] (TUI; realistic security events for EDR/detection lab testing) exercise the same telemetry surface from the generation side (source: wiki/sources/descriptions/zodiacon__EtwExplorer.md) (source: wiki/sources/descriptions/xuanxuan0__TiEtwAgent.md) (source: wiki/sources/descriptions/rabbitstack__fibratus.md) (source: wiki/sources/descriptions/progmboy__openprocmon.md) (source: wiki/sources/descriptions/olafhartong__BamboozlEDR.md); ETW Testing / threat-tracing disable samples such as [[disable-threat-tracing]] (C; Anti Cheat stress-testing) sit on the disable/blind side of that ThreatIntel lane (source: wiki/sources/descriptions/muturikaranja__disable-threat-tracing.md); minimal AMSI + ETW byte-patch PoCs such as [[amsi-etw-patch]] (Mr-Un1k0d3r; C/PowerShell/C#; branch-logic patches in AMSI paths + telemetry short-circuit; control-flow diagrams; red-team / defensive in-memory tampering detection validation; README [ETW Testing]) (source: wiki/sources/descriptions/Mr-Un1k0d3r__AMSI-ETW-Patch.md); kernel callback/ETW enumeration + disable tooling such as [[telemetry-sourcerer]] (unsigned driver; test signing / DSE / cert signing; Cheat Windows kernel explorer) extends the same lane (source: wiki/sources/descriptions/jthuraisamy__TelemetrySourcerer.md) - **Host XDR / HIDS:** enterprise agent–manager platforms such as [[wazuh]] (intrusion detection, FIM, log correlation, Elasticsearch viz; Linux/Windows/macOS) illustrate SOC-style endpoint telemetry adjacent to AC/EDR research under README `[XDR]`. (source: wiki/sources/descriptions/wazuh__wazuh.md) Archived incident-response case-management platforms such as [[the-hive]] (TheHive-Project; Scala backend + web UI; SOC alert triage and case workflows; historical snapshot for studying legacy IR architecture; README [EDR]) illustrate complementary SOC operational tooling beside endpoint telemetry stacks. (source: wiki/sources/descriptions/TheHive-Project__TheHive.md) Lightweight anti-ransomware tooling such as [[raccine]] (Neo23x0; debugger registration for `vssadmin`/`wmic`; YARA command-line matching; parent-chain termination + logging; no resident agent; blocks shadow-copy deletion; README [EDR]) illustrates defensive incident-prevention beside full EDR agents. (source: wiki/sources/descriptions/Neo23x0__Raccine.md) Open-source active-defense EDR such as [[bluespawn]] (ION28; Hunt/Mitigate/Monitor/Scan; ATT&CK detections, YARA, ETW monitoring, automated quarantine/process suspension; C++; rule-driven content; README [EDR]) illustrates full-stack endpoint defense beside SOC telemetry stacks. (source: wiki/sources/descriptions/ION28__BLUESPAWN.md) Open-source EDR reference such as [[openedr]] (Comodo Security; C++; system monitoring, event collection, threat detection, AWS SDK cloud analysis; real-time Windows endpoint telemetry/response; EDR architecture study; README [EDR]) complements that full-stack defensive lane. (source: wiki/sources/descriptions/ComodoSecurity__openedr.md) Open-source detection-driven-response EDR such as [[whids]] (0xrawsec; Go; ETW + Sysmon telemetry; Gene rule engine; alert-triggered artifact collection—files, registry, process memory; manager service + admin API; incident response / enterprise endpoint monitoring with transparent customizable detection; README [EDR]) illustrates ETW/Sysmon-driven IR beside full-stack EDR references. (source: wiki/sources/descriptions/0xrawsec__whids.md) Experimental Rust EDR PoC such as [[sanctum]] (0xflux; kernel driver + user-mode engine + Tauri UI; process/thread/filesystem/syscall monitoring; ETW consumers, minifilter, kernel hooking/containment; low-level defensive tooling research; README [EDR]) illustrates kernel+ETW endpoint-agent prototyping beside full-stack open-source EDR. (source: wiki/sources/descriptions/0xflux__Sanctum.md) Agent–manager endpoint protection such as [[stresser]] (AvivShabtay; C++ UM/KM host agents + centralized policy/response; ETW-driven telemetry, artifact processing, dynamic/static detection; malware-defense and AC-adjacent endpoint experiments; README Anti Virus in fact but also Anti Cheat) sits in the same ETW/EDR research lane. (source: wiki/sources/descriptions/AvivShabtay__Stresser.md) - **AC driver implementation research:** full C++ kernel driver reimplementations such as [[equ8-poc]] (EQU8 `.sys` from companion article; IOCTL/callback/driver-comm study for explore anticheat:equ8) complement userspace protocol emulators, user-mode IOCTL-handle teardown such as [[equ8-bypass]] (registry driver-path discovery + handle close), and IRP-abuse PoCs when studying proprietary AC driver internals. (source: wiki/sources/descriptions/kkent030315__EQU8-PoC.md) (source: wiki/sources/descriptions/hotline1337__equ8_bypass.md) Kernel-mode AC development platform [[uac]] (c4kef; Visual Studio driver with common cheat-technique detection routines; C++ framework for validating kernel-level detection methods; cheat developer platform lane) extends the same reference-implementation lane. (source: wiki/sources/descriptions/c4kef__UAC.md) - **SMM (System Management Mode):** Ring -2 firmware-resident execution in SMRAM, below the OS and typical hypervisor introspection; SMM cheat samples such as [[smm]] (ekknod; C/C++; driver development, graphics, networking; cheat / SMM) and SMM backdoor research frameworks such as [[smm-infect]] (Oliver-1-1; UEFI/EDK2 SMI handler + Windows/Linux user-mode clients; BIOS patching docs; firmware trust-boundary / high-privilege persistence research; README [SMM Driver]) and [[smm-backdoor-ng]] (Cr4sh; UEFI DXE + SMM firmware + Python Windows/Linux clients; flash-image infection or pre-boot DMA-assisted loading; privilege-escalation and hypervisor-interaction demos; firmware persistence / pre-OS research; README [UEFI backdoor]) sit in the same below-OS offensive lane as EFI bootkits and [[dma]] when studying AC evasion. (source: wiki/sources/descriptions/ekknod__smm.md) (source: wiki/sources/descriptions/Oliver-1-1__SmmInfect.md) (source: wiki/sources/descriptions/Cr4sh__SmmBackdoorNg.md) - **Hypervisor defense:** EPT write-trap on callback lists, ETW structures, and EPP driver pages — guest kernel R/W cannot silently remove second-stage permissions when hypervisor policy remains trustworthy; complements [[hvci]] W→X enforcement; defensive Intel host hypervisor [[novahypervisor]] (Idov31; C++/asm Windows kernel driver + client; per-address R/W/X memory policies; mitigates BYOVD-style kernel attacks; endpoint/AC research; README defensive x64 Intel host based hypervisor) (source: wiki/sources/descriptions/Idov31__NovaHypervisor.md); WHP research tracing; WHP user-mode x64 PE emulation such as [[winvisor]] (`Windows Emulator` lane); KVM-on-Windows Android Emulator acceleration via [[android-emulator-hypervisor-driver]] (Google; port of KVM to Windows 8.1+ x64; mobile/emulator research host) (source: wiki/sources/descriptions/google__android-emulator-hypervisor-driver.md); minimal Linux KVM VMM + guest-kernel tutorial such as [[kvm-kernel-example]] (david942j; QEMU-like hypervisor + custom guest kernel with hypercalls, mmap, syscalls, ELF load; guide for KVM/hypervisor internals) (source: wiki/sources/descriptions/david942j__kvm-kernel-example.md); Linux KVM guest introspection framework [[introvirt]] (IntroVirt; patched KVM + C++ userland; runtime guest memory/execution inspect/control; process/thread APIs, breakpoints, syscall visibility; Windows/Linux guest malware/AC research in VMs; README Guest introspection library) (source: wiki/sources/descriptions/IntroVirt__IntroVirt.md); upstream Oracle VirtualBox VMM such as [[virtualbox]] (open-source x86_64 hypervisor; CPU/memory virtualization, device emulation, guest additions, COM/IOCTL driver interfaces; hardware-virtualization and VMM-internals study baseline) (source: wiki/sources/descriptions/VirtualBox__virtualbox.md); RING3 kernel-driver emulation such as [[kace]] (self context mapping or Unicorn; PE mapping, memory tracking, anti-debug/anti-emulation monitoring; sandboxed AC/driver analysis; Qfrost911 fork) (source: wiki/sources/descriptions/Qfrost911__KACE.md); title-specific userspace AC-driver protocol emulators such as [[holodori-kernel-bypass]] (holo-emu; fake `usrdrv017964.sys` for Hololive Dreams on native/Wine/Proton without loading the real `.sys`) (source: wiki/sources/descriptions/redecorate__Holodori-Kernel-Bypass.md); hacked-hypervisor stress/test tooling such as [[vt-debuuger]] and VT debugger research such as [[erisdbg]] (C/C++; kernel drivers / modding; cheat / debugging lane) (source: wiki/sources/descriptions/kkpwn__ErisDbg.md); Intel VT-x anti-debug–invisible debugger [[vt-debuger]] (thin hypervisor; VM-exit breakpoints/single-step/memory watch; protected-software RE) (source: wiki/sources/descriptions/gmh5225__vt-debuger.md); open-source hypervisor-assisted debugger [[hyperdbg]] (HyperDbg; C/C++; Intel VT-x/EPT; user-mode + kernel-mode; stealth breakpoints, hidden hooks, memory-access monitoring; RE / fuzzing / malware / anti-cheat research; README [VT debuger]) (source: wiki/sources/descriptions/HyperDbg__HyperDbg.md); x64dbg/x32dbg hypervisor anti-anti-debug plugin [[hyperhide]] (Air14; kernel driver + VT-x/EPT; PEB/thread/process flags + Nt* sanitization; 64-bit Windows; README [VT debuger]) (source: wiki/sources/descriptions/Air14__HyperHide.md); Unreal-focused VT-x/EPT kernel debugging via [[unreal-vtdbg]] (Delphi UI + VMX/EPT/vmcall driver, EPT hooks, Detours breakpoints, Win10/11 builds; authorized AC/RE on protected UE processes) (source: wiki/sources/descriptions/xhscfq__UnrealVTDbg.md); AMD SVM / Rust hacked-hypervisor testing such as [[baresvm]]; AMD SVM hacked-hypervisor feature walkthroughs such as [[aether-visor]] (gmh5225; implementation-focused; `Detection: Hacked Hypervisor Testing AMD`) (source: wiki/sources/descriptions/gmh5225__AetherVisor.md); AMD SVM Type-1 process-protection / stealth-debug stacks such as [[powervm]] (NPT hooks, CPUID hypercall memory reads, shadow DebugPort; CE fork for VMProtect/ACE-protected targets; Win10/11 AMD SVM) (source: wiki/sources/descriptions/not1cyyy__PowerVM.md); minimal VT-x Type-2 learning drivers such as [[hv]] (VMX root / VMCS / CPUID-MSR-CR exits); progressive VT-x tutorial such as [[hypervisor-from-scratch]] (SinaKarvandi; C/C++/asm; staged VMX setup, VMCS, EPT translation, OS virtualization; educational hypervisor-analysis foundation; README [Hypervisor]) (source: wiki/sources/descriptions/SinaKarvandi__Hypervisor-From-Scratch.md); stealth Type-2 research such as [[ophion]] (EPT, CPUID cache, CR4.VMXE hide, TSC compensation, private host CR3); experimental Type-2 EPT hooking such as [[hypervisor]] (momo5502; WDK driver + UM lib; EPT page hooks, violation watchpoints, per-process cleanup; integrity-check bypass research) (source: wiki/sources/descriptions/momo5502__hypervisor.md); VT-x/EPT user-mode **memory deception** such as [[notruth]] (KelvinMsft; C/C++ kernel driver + test components; redirect reads to fake values while controlling execution semantics; checksum/integrity bypass experiments; README Hide Memory By VT) (source: wiki/sources/descriptions/KelvinMsft__NoTruth.md); educational Intel VT-x research HV as UEFI + Windows drivers such as [[minivisorpkg]] (pre-OS inspect; WinDbg-friendly); Microsoft Hyper-V memory introspection / RE such as [[hyper-rev]] (structures, hypercalls, partitions, VP / memory virtualization) (source: wiki/sources/descriptions/noahware__hyper-reV.md); Hyper-V offensive hacking framework such as [[voyager]] (backengineering upstream; Win10 x64 AMD & Intel; builds 1507–2004; cheat / windows kernel explorer; [[vdm]]/[[msrexec]] ecosystem) (source: wiki/sources/descriptions/backengineering__Voyager.md); Voyager-style UEFI boot-time hypervisor loader [[modded-voyager]] (NurdAlert; Intel/AMD VM-exit handlers + GPA/GVA R/W primitives; hooks `bootmgfw`/`winload` + Hyper-V paths pre-OS; boot-time virtualization / kernel-control research) (source: wiki/sources/descriptions/NurdAlert__modded-voyager.md); runtime Hyper-V VM-exit hijacking via DDMA-style DMA such as [[diskjacker]] (LabGuy94; C++ kernel + usermode + asm stubs; low-level mapping and execution transfer; hardware/virtualization preconditions; hypervisor security PoC) (source: wiki/sources/descriptions/LabGuy94__Diskjacker.md); FPGA PCIe DMA Hyper-V VM-exit backdoor + pre-boot UEFI DXE injection PoCs such as [[s6-pcie-microblaze]] (Cr4sh; SP605 Spartan-6 endpoint + MicroBlaze; raw TLP over Ethernet; guest-to-host escape + runtime Boot Backdoor shell/file transfer; complements [[diskjacker]] on the DMA-assisted hypervisor research lane) (source: wiki/sources/descriptions/Cr4sh__s6_pcie_microblaze.md) and compact autonomous pre-boot implant flows such as [[pico-dma]] (Cr4sh; Verilog + Vivado/Vitis + MicroBlaze; UART or autonomous payload execution; SPI flash; boot/firmware + DMA implant prototyping) (source: wiki/sources/descriptions/Cr4sh__pico_dma.md); reusable Hyper-V impersonation / hypercall-intercept library such as [[hyperdeceit]] (Xyrem; C++; ready-to-hook TLB flush, sleep/shutdown, address-space switch, spinlock paths; kernel compatibility focus; README `[HvcallCodeVa]`) (source: wiki/sources/descriptions/Xyrem__HyperDeceit.md); HvcallCodeVa address-space-switch hypercall-callback hook PoC such as [[hook-hvcall-code-va]] (1401199262; C++ kernel PoC; pattern-scan internal routines; custom hypercall code callback + runtime enlightenment-flag adjustment; per-processor hypercall page setup + CR3 handling; kernel internals / hypervisor-behavior research; README `[HvcallCodeVa]`) (source: wiki/sources/descriptions/1401199262__HookHvcallCodeVa.md); backengineering Tb-monitoring PoC such as [[poc-exflushtb]] (C++; asset-pipeline oriented; Some Tricks / Windows Ring0; README “A POC for monitoring Tb”) (source: wiki/sources/descriptions/backengineering__POC-ExFlushTb.md); LoL-focused hypervisor-assisted offensive stacks such as [[vanderleague]] (gmh5225; C/C++; kernel driver + rendering; cheat / game:lol) (source: wiki/sources/descriptions/gmh5225__VanderLeague.md); user-mode HV presence checks such as [[checkhv-um]] (CPUID leaf / RDTSC timing / VMCS artifacts / signatures, no driver); multi-technique C++ detectors such as [[hypervisor-detection]] (`Detection: Hacked Hypervisor`); IDT SIDT/LIDT hypervisor probes such as [[hv-detect]] (gmh5225; controlled IDT context with post-check restore) (source: wiki/sources/descriptions/gmh5225__hv-detect.md); Go Hyper-V VM environment probes such as [[go-detection-hyper-v]] (CPUID feature checks, timing, hypervisor presence; gmh5225) (source: wiki/sources/descriptions/gmh5225__Go-Detection-Hyper-v.md); kernel-mode KPCR/KPRCB Hyper-V guest probes such as [[detection-hyper-v]] (gmh5225; Win10 17763; `PowerState.Hypervisor` / `HvTargetState` via KeGetPcr→CurrentPrcb; debug print + `STATUS_VIRUS_INFECTED` exit; `[Hyper-v]`) (source: wiki/sources/descriptions/gmh5225__Detection-Hyper-v.md); ring-0 multi-heuristic hypervisor test driver such as [[detect-hypervisor-detect-ring-0]] (gmh5225; CPUID hypervisor bit + leaf comparisons, TSC/APERF/MPERF VM-exit timing, Intel LBR/DEBUGCTL consistency; manual-map print harness from DriverEntry; Secret Club research lineage; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/gmh5225__Detect-Hypervisor_detect_ring_0.md); hypervisor VM-detection benchmarking such as [[nohv]] (C/C++ kernel driver; common vm-detection benchmark suite) (source: wiki/sources/descriptions/jonomango__nohv.md); cross-platform VM environment detection such as [[vmaware]] (header-only C++; 100+ guest hypervisor/VM artifact checks; confidence API; `Detection:Virtual Environments`) (source: wiki/sources/descriptions/kernelwernel__VMAware.md); user-mode EPT hook detectors such as [[ept-hook-detection]] (timing latency, write-and-compare on code pages, cross-core consistency; `Detect EPT`) (source: wiki/sources/descriptions/momo5502__ept-hook-detection.md); VPGATHER / vectored-exception EPT/NPT probes such as [[bloodhound]] (Skeletal-Group; C++ user-mode library; stealthier executable/readable page-state transition checks; hypervisor hook detection PoC; Various novel EPT/NPT hook detection mechanisms) (source: wiki/sources/descriptions/Skeletal-Group__Bloodhound.md); REP MOV / ERMSB side-channel EPT probes such as [[ermsb-meme]] (everdox; C; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/everdox__ermsb-meme.md); REP MOVS fault-vs-uninterrupted EPT PoC such as [[rep-mov-ept-detecc]] (JustasMasiulis; Windows C++; overwrite-pattern signal + exception handling; `REP MOV based EPT detection`) (source: wiki/sources/descriptions/JustasMasiulis__rep_mov_ept_detecc.md); STR-exit VMM fault probes such as [[vmdtstr]] (cryotb; nested HVPP test harness; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/cryotb__VmdtStr.md); broad x86-64 HV/VMM detection collection such as [[hvdetecc]] (can1357; processor/PMC/TLB/timing/MSR/interrupt tests; Intel VMX + AMD SVM; Type-1 via SMBIOS/ACPI/PCI; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/can1357__hvdetecc.md) (source: wiki/sources/descriptions/x86matthew__WinVisor.md) (source: wiki/sources/descriptions/waryas__KACE.md) (source: wiki/sources/descriptions/zxd1994__vt-debuuger.md) (source: wiki/sources/descriptions/valium007__BareSVM.md) (source: wiki/sources/descriptions/gmh5225__AetherVisor.md) (source: wiki/sources/descriptions/zer0condition__hv.md) (source: wiki/sources/descriptions/zer0condition__Ophion.md) (source: wiki/sources/descriptions/tandasat__MiniVisorPkg.md) (source: wiki/sources/descriptions/zer0condition__checkhv_um.md) (source: wiki/sources/descriptions/void-stack__Hypervisor-Detection.md) - **EFI:** pre-kernel mappers that skip normal driver-load telemetry — e.g. [[xigmapper]] (EFI manual map; payload must not be USB-hosted when studying early-load AC such as [[vanguard]]) (source: wiki/sources/descriptions/xtremegamer1__xigmapper.md); focused EFI manual-map implementations such as [[sumap]] (ekknod; C/C++; driver development / memory analysis; cheat / EFI Manual Map) (source: wiki/sources/descriptions/ekknod__sumap.md); Rust UEFI boot mapper such as [[valthrun-uefi-mapper]] (Valthrun; x86_64 UEFI target; bootable ISO/USB deployment; loads game driver before normal OS drivers; boot-time driver loading and stealth-oriented security research; cheat / EFI Manual Map) (source: wiki/sources/descriptions/Valthrun__valthrun-uefi-mapper.md); integrated UEFI memory/process manipulation frameworks such as [[advanced-efi-driver-with-gdi-and-kernel-mouse-input]] (Twobot7; C/C++; driver-level memory ops + GDI overlay renderer + kernel mouse input; encrypted command channels + anti-detection validation; game security experimentation; cheat / EFI driver) (source: wiki/sources/descriptions/Twobot7__advanced-efi-driver-with-gdi-and-kernel-mouse-input.md); PatchGuard-safe **`MmCopyMemory`** hook research such as [[efi-monitor]] (ekknod; C/C++; driver development / graphics / networking; cheat / EFI driver area; README `[Hooking MmCopyMemory PG safe]`) (source: wiki/sources/descriptions/ekknod__efi-monitor.md); custom **`KiSystemStartup`** hook research such as [[ki-system-startup-meme]] (ekknod; C/C++; kernel-level driver development / graphics; cheat / EFI driver area; README `[Custom KiSystemStartup]`) (source: wiki/sources/descriptions/ekknod__KiSystemStartupMeme.md); EFI **GetVariable**-backed RPM samples such as [[sub-get-variable]] (ekknod; C/C++; kernel-level driver development / graphics; cheat / EFI RPM; README `[EFI RPM]`) (source: wiki/sources/descriptions/ekknod__SubGetVariable.md); simple UEFI runtime-driver mappers such as [[uefi-bootloader]] (C/C++; cheat / EFI driver research) (source: wiki/sources/descriptions/sa413x__UEFI-Bootloader.md); generic UEFI bootkit PoCs such as [[bootlicker]] (patches Boot Manager / OS loader pre-kernel; DSE / [[patchguard]] / Secure Boot research; initial usermode execution; gmh5225) (source: wiki/sources/descriptions/gmh5225__bootlicker.md); portable x64 UEFI bootkit such as [[efiguard]] (Mattiwatti; C/C++ + EDK2; patches Windows boot chain to disable PatchGuard + DSE at startup; runtime disassembly; SetVariable-based boot-time patch modes; EfiDSEFix helper; wide Win x64 version support; boot integrity / kernel protection / AC driver-load bypass research; README [EFI]) (source: wiki/sources/descriptions/Mattiwatti__EfiGuard.md); Windows bootloader shim PoCs such as [[pwnedboot]] (SamuelTulach; C/C++ + gnu-efi; replaces microcode-update DLL for very-early custom code; bootloader executes replacement under specific boot options then remaps to continue boot; Secure Boot bypass / early-boot attack surface research; pre-OS AC threat modeling) (source: wiki/sources/descriptions/SamuelTulach__PwnedBoot.md); compact UEFI boot-chain PoCs such as [[uefi-bootkit]] (ajkhoury; mostly C; UEFI application + runtime driver; persists past ExitBootServices into OS boot; EFI build/image load/runtime protocol handling; pre-OS persistence + detection research) (source: wiki/sources/descriptions/ajkhoury__UEFI-Bootkit.md); staged EFI→kernel boot-stage implant frameworks such as [[driver-efi-bootkit]] (gmh5225; hooks `ExitBootServices`/`SetVirtualAddressMap`; patches `OslArchTransferToKernel`; repurposes target driver `.rsrc` + `MmMapIoSpace`; Python BOOTDOOR EFI inject; optional `bootmgfw` integrity bypass; boot/firmware/kernel RE) (source: wiki/sources/descriptions/gmh5225__Driver-efi-bootkit.md); UEFI boot-stage HWID spoof driver research such as [[rainbow-efi]] (gmh5225; EDK II build env + `rainbow.efi`; `ExitBootServices` → `OslLoaderBlock` walk → `IopLoadDriver` hook for pre-kernel spoofing; OVMF/shell ISO/ROM debug assets; firmware/boot RE; cheat / HWID) (source: wiki/sources/descriptions/gmh5225__-Rainbow---EFI.md); UEFI bootkit research such as [[rainbow]] (SamuelTulach; EDK-II pre-kernel bootkit; OVMF/QEMU debug + VS UEFI build; pre-boot attack vectors / firmware persistence / HWID research; cheat / HWID) (source: wiki/sources/descriptions/SamuelTulach__rainbow.md); boot-time SMBIOS spoofing such as [[negativespoofer]] (SamuelTulach; Clover-style firmware-table patch before OS start; C/EFI; pre-OS hardware identity signals for anti-cheat HWID research; cheat / HWID) (source: wiki/sources/descriptions/SamuelTulach__negativespoofer.md); lightweight reusable UEFI SMBIOS table library such as [[perfectsmbios]] (Th3Spl; locates SMBIOS 2.0/3.0 entry points pre-OS; structure lookup + randomized string spoof helpers; avoids Windows kernel boot-chain pointers; VisualUefi/EDK2; Windows+Linux; firmware HWID / anti-cheat research; cheat / EFI Driver) (source: wiki/sources/descriptions/Th3Spl__PerfectSMBios.md); OS-runtime UEFI memory-access cheats such as [[fortnite-efi-external]] (gmh5225; external Fortnite; UEFI runtime services + `NtSetSystemEnvironmentValueEx` usermode↔UEFI comm; no Windows `.sys` load; anti-cheat driver-detection evasion) (source: wiki/sources/descriptions/gmh5225__Fortnite-EFI-External.md); Valorant external EFI manual-map cheat drivers such as [[ue4-c-]] (frankelitoc; kernel driver manual-mapped via EFI; IOCTL dispatch-hook KM↔UM comm; cross-process UE4 memory reads; cheat / game:valorant [External]) (source: wiki/sources/descriptions/frankelitoc__UE4-c-.md); minimal EFI runtime process dump/R/W PoCs such as [[efidump]] (gmh5225; gnu-efi `driver.efi` + post-boot Windows client; EDK2 shell load; no hardening; cheat / [Dump]) (source: wiki/sources/descriptions/gmh5225__EfiDump.md); EFI boot-time privileged memory access such as [[efi-driver-access]] (TheCruZ; GNU-EFI runtime driver loaded at boot + Visual Studio usermode client for read/write/process-base; build/boot workflow docs; kernel + AC bypass pre-OS path research; cheat / EFI RPM) (source: wiki/sources/descriptions/TheCruZ__EFI_Driver_Access.md); SetVariable-hook EFI runtime virtual-memory R/W PoC such as [[efi-memory]] (SamuelTulach; firmware-side runtime driver + usermode companion; EfiGuard-inspired SetVariable comm; kdmapper-style mapper client; firmware security / pre-OS memory access research; cheat / EFI RPM) (source: wiki/sources/descriptions/SamuelTulach__efi-memory.md); title-integrated Apex Legends EFI cheat such as [[direct-efi-apex-cheat]] (TheCruZ; user-mode client + UEFI runtime component; runtime variable hooks + kernel function pointers bridged from EFI; glow/aim assistance; firmware-assisted AC bypass research; cheat / game:apex legends) (source: wiki/sources/descriptions/TheCruZ__Direct-EFI-Apex-Cheat.md); in-RAM `SYSTEM` hive patching at `ExitBootServices` such as [[efitool]] (SYSTEM shell before logon; no disk writes / no kernel driver; BitLocker PCR notes) (source: wiki/sources/descriptions/wesmar__EfiTool.md); [[undervolter]] (wesmar; native UEFI x64 Intel CPU undervolting via MSR/MMIO before OS/hypervisor; FIVR MSR 0x150; NVRAM Setup/CFG Lock unlock; Secure Boot SelfEnroll; bypasses Hyper-V/VBS MSR filtering; Sandy Bridge–Arrow Lake; Plundervolt-class pre-boot research; cheat / EFI Driver) (source: wiki/sources/descriptions/wesmar__UnderVolter.md); native UEFI x64 NTFS read/write via [[ntfs-efi]] (EfiNtfs; `EFI_SIMPLE_FILE_SYSTEM_PROTOCOL`; pre-boot bootloader/driver staging and offline disk edits; chkdsk-clean unmount; MSVC + prebuilt EDK2) (source: wiki/sources/descriptions/wesmar__NTFS_EFI.md); user-mode Windows API ESP mount samples such as [[mount-system-partition]] (brew02; C++; partition enumeration + mount without external tools; programmatic access to hidden EFI system partition; UEFI security / firmware RE) (source: wiki/sources/descriptions/brew02__MountSystemPartition.md); kernel-level NTFS secure-deletion research such as [[antfs]] (ch3rn0byl; WDK driver overwrites MFT records and file content; paired user-mode MFT recovery console; VS2019; Delete File / anti-forensics) complements pre-OS NTFS access for studying filesystem-level evidence removal (source: wiki/sources/descriptions/ch3rn0byl__ANTfs.md); minimal CMake + MSVC scaffold for standalone `.efi` apps via [[eficmake]] (EDK2 headers without full EDK2 build; `/SUBSYSTEM:EFI_APPLICATION`; boot-services entry) (source: wiki/sources/descriptions/mrexodia__EfiCMake.md); Visual Studio + EDK-II UEFI dev scaffold via [[simpleuefi]] (Th3Spl; MSVC project templates, property sheets, Python setup; bootstrap UEFI apps without full EDK-II build complexity; UEFI security / bootkit dev) (source: wiki/sources/descriptions/Th3Spl__SimpleUEFI.md); GNU-EFI Visual Studio template via [[easyuefi]] (SamuelTulach; C/asm + linker scripts + bundled GNU-EFI; ready-to-build Windows research scaffold; firmware security / boot-stage experimentation / low-level game-security tooling prototypes; README [Visual Studio template for GNU-EFI]) (source: wiki/sources/descriptions/SamuelTulach__EasyUefi.md); VisualUEFI-style Clang + DWARF source-level UEFI debugging via [[visualuefi-2-0]] (Shtan7; C/C++ samples + EDK2 + Visual Studio; VMware + CLion remote GDB; firmware/boot-time RE) (source: wiki/sources/descriptions/Shtan7__VisualUEFI-2.0.md); C++ UEFI graphics framework via [[uefi-graphic]] (Oliver-1-1; VisualUefi workflow; framebuffer classes for screens/colors/text/shapes; mouse input + simple file ops; pre-boot graphical tooling for firmware dev / low-level security research; README [Simpel usage of graphic in UEFI]) (source: wiki/sources/descriptions/Oliver-1-1__UEFI-Graphic.md); ACPI BGRT boot-logo replacement such as [[bgrt-injector]] (Jamesits; C UEFI loader/driver; custom 24-bit BMP assets; rEFInd + default EFI path integration; firmware customization / boot-chain experimentation; README [Changes the boot screen image on a UEFI computer]) (source: wiki/sources/descriptions/Jamesits__BGRTInjector.md); fully scriptable UEFI bootloaders such as [[luaboot]] (Lua-driven pre-OS boot; MIT; cheat / EFI driver research) (source: wiki/sources/descriptions/leap0x7b__luaboot.md); educational research HVs with a UEFI-driver path such as [[minivisorpkg]] (pre-boot inspect alongside a Windows-driver debug build) (source: wiki/sources/descriptions/tandasat__MiniVisorPkg.md); IDA-side UEFI binary annotation via [[ida-efiutils]] (protocol GUIDs, Boot/Runtime Services, PEI/DXE entry points; `[EFI binaries]`) (source: wiki/sources/descriptions/snare__ida-efiutils.md); automated UEFI firmware analysis via [[efixplorer]] (EFI protocol GUID matching; Boot/Runtime Services annotation; PEI/DXE driver dependency reconstruction; bootkit/EFI malware RE; gmh5225) (source: wiki/sources/descriptions/gmh5225__efiXplorer.md); Ghidra-side UEFI binary annotation via [[efiseek]] (DSecurity; Java analyzer plugin; EFI GUID/protocol/callback relationship automation; headless firmware analysis workflows; complements [[efixplorer]] and [[ida-efiutils]]) (source: wiki/sources/descriptions/DSecurity__efiSeek.md); Go UEFI firmware image parse/create/manipulate toolkit via [[fiano]] (Firmware Volumes, FFS, PE32, LZMA/Tiano, GUIDed sections; extract/replace/remove flash modules; firmware security / boot analysis) (source: wiki/sources/descriptions/linuxboot__fiano.md); AMD Secure Processor (PSP) firmware RE via [[amd-sp-loader]] (Binary Ninja loader; ABL/PSP bootloader load addresses; PSP syscall annotation; PSPTool workflow; bootloader-chain analysis; dayzerosec; `[AMD-SP or PSP firmware]`) (source: wiki/sources/descriptions/dayzerosec__AMD-SP-Loader.md); Hackintosh OpenCore EFI packs such as [[x260-lenovo-opencore]] (ThinkPad X260) are a separate EFI lane for macOS-on-PC research hosts rather than cheat mapping. (source: wiki/sources/descriptions/x90skysn3k__x260-lenovo-opencore.md); legacy BIOS MBR bootkit PoCs such as [[openpetya]] (Petya-inspired; custom MBR/stage-2 Real→Protected Mode; NTFS MFT Salsa20 encryption; Assembly/C/C++; educational pre-OS RE) (source: wiki/sources/descriptions/iss4cf0ng__OpenPetya.md) - **Legitimate-driver hijack / stealth I/O:** research such as [[boom]] and [[driver-read-write]] hijack `Beep.sys` and change communication so Ring0↔usermode paths are less obvious to AC telemetry; [[driver-read-write]] (gmh5225; manually mapped KM R/W via `IRP_MJ_DEVICE_CONTROL` swap; process attach + module-base queries; PiDDBCacheTable/MmUnloadedDrivers cleanup; README `[Hijack IRP Beep.sys]`) (source: wiki/sources/descriptions/gmh5225__Driver-read_write.md); SpeedFan.sys dispatch hijack PoCs such as [[swap-control-ioctl]] (Barracudach; kernel PoC; `IRP_MJ_DEVICE_CONTROL` dispatch-pointer trampoline redirect; custom ioctl handlers for process memory copy/allocation/protection and module-base lookup; driver communication hook + AC detection study; README `[Hijack IRP SpeedFan.sys]`) (source: wiki/sources/descriptions/Barracudach__Swap-control-ioctl.md); no-image driver hijack PoCs such as [[driver-driver-no-image]] (gmh5225; shellcode injected into another driver's dispatch path—e.g. NTFS handlers—via inline jumps with WP disable and trampolines; no conventional standalone driver image; README `[Hijack Driver]`) (source: wiki/sources/descriptions/gmh5225__Driver-DriverNoImage.md); defensive export-trampoline scanners such as [[driver-detect-nullshit]] (gmh5225; walks export tables of win32kfull.sys, win32kbase.sys, dxgkrnl.sys, ntoskrnl.exe for mov rax, imm64; jmp rax patches with targets outside the owning image; README Null driver detector) (source: wiki/sources/descriptions/gmh5225__Driver-Detect-nullshit.md); `IRP_MJ_DEVICE_CONTROL` dispatch integrity scanners such as [[device-control-hooks-scanner]] (Luchinkin; KMDF driver walks `\Driver` object directory; flags device-control handlers outside owning driver image bounds with module resolution for foreign pointers; kernel integrity auditing / driver hook detection; README [device-control-hooks-scanner]) (source: wiki/sources/descriptions/Luchinkin__device-control-hooks-scanner.md); ntoskrnl memory-vs-disk integrity verification such as [[detect-ntoskrnl-integrity]] (DejavuSecure; C++; validate in-memory ntoskrnl against on-disk image; SSDT transforms, page-table randomization, retpoline-era behavior; anti-rootkit / AC / defensive kernel security research; README [Memory Integrity Verification with Disk Verification of ntoskrnl.exe]) (source: wiki/sources/descriptions/DejavuSecure__DetectNtoskrnlIntegrity.md); composition-surface channels such as [[data-ptr-swap]] (`NtSetCompositionSurfaceAnalogExclusive`) sit in the same cheat / driver-communication lane; older gmh5225 win32kbase data-ptr swap samples such as [[dataptrswap-driver]] (scan win32kbase; `InterlockedExchangePointer` hook on `NtSetCompositionSurfaceAnalogExclusive`; explorer.exe attach; bundled MmUnloadedDrivers cleanup; README `[NtSetCompositionSurfaceAnalogExclusive]`) extend that lane (source: wiki/sources/descriptions/gmh5225__DataPtrSwap-driver.md); Win11 gesture-config data-ptr hooks such as [[dataptrhookwin11]] (`NtUserSetGestureConfig`) sit in the same lane; `Afd.sys` `.data` pointer hooks on `AfdIrpCallDispatch` such as [[afd-irp-call-dispatch]] sit in the same lane; [[data-communication]] (Sinclairq; C++ kernel driver + usermode client; kernel `.data` pointer swap for high-speed KM↔UM messaging and R/W; pattern scan + process-base helpers; stability risks on protected systems; README `[NtCompareSigningLevels]`; kernel research / AC experimentation) (source: wiki/sources/descriptions/Sinclairq__DataCommunication.md); [[double-data-pointer]] (Astronaut00; C++ kernel PoC; double-pointer KM↔UM channel for manually mapped driver; virtual/physical memory R/W; PFN cleanup + pool artifact reduction with documented detection risks; anti-cheat bypass / low-level game security research; README `[Double Data Pointer]`) (source: wiki/sources/descriptions/Astronaut00__DoubleDataPointer.md); [[ntcomparesigninglevel-hook]] (ExpLife0011; C/C++ paired kernel driver + usermode controller; function-pointer swap inside `NtCompareSigningLevels` for covert KM↔UM comm; repo marks approach abandoned — PatchGuard instability; historical signing-level hook / AC bypass research; README `[NtCompareSigningLevels]`) (source: wiki/sources/descriptions/ExpLife0011__NtCompareSigningLevel-hook.md) sit in the same `.data`-pointer covert-comms lane; WPP trace-infrastructure hijack PoCs such as [[wpp]] (btbd; `.data` WPP function-pointer swap in `disk.sys`/`mountmgr.sys`; DeviceControl interception via return-address checks + IRP extraction; HWID disk-serial research) sit in the same lane (source: wiki/sources/descriptions/btbd__wpp.md); IRP Null hijack research such as [[gina-public]] sit in the same lane; kernel DWM composition samples such as [[double-callback]] (C/C++; DWM in kernel / render-draw) and [[kernel-dwm]] (cs1ime; C driver; hooks DWM composition DirectX from Ring0; injects compositor draw commands; README `[DWM In Kernel]`; stealth overlay research) (source: wiki/sources/descriptions/cs1ime__KernelDwm.md) ride the same composition stack from Ring0; hook-free GDI kernel drawing PoCs such as [[kernel-drawing]] (Sentient111; spoofed thread context to call GDI kernel paths without traditional hooks; version-dependent NT offsets; README Drawing from kernelmode without any hooks) extend that Ring0 render-draw lane beside [[krnl-gdi-render]]. (source: wiki/sources/descriptions/Sentient111__KernelDrawing.md) `NtGdiDdDDISubmitCommand` + InfinityHook GDI draw PoCs such as [[kernel-gdi-draw]] (BadPlayer555; win32k GDI routines; screen-update-synchronized Ring0 overlay; README `[Kernel + GDI]`) sit in the same lane. (source: wiki/sources/descriptions/BadPlayer555__KernelGDIDraw.md) Full-game kernel GUI demo [[ntdoom]] (NSG650; C/C++ driver; PureDOOM port; win32k syscall handling + thread context spoofing + kernel graphics/input; extreme NT GUI/syscall research; README Doom running in the NT kernel) extends that lane as an end-to-end gameplay loop from Ring0. (source: wiki/sources/descriptions/NSG650__NtDOOM.md) Win11 Null driver-cheat reimplementations such as [[nulldriver-cheat]] (gmh5225; hooks `NtOpenCompositionSurfaceSectionInfo` in dxgkrnl for covert user↔kernel module-base / process R/W and optional win32k GDI draw helpers; README `[NtOpenCompositionSurfaceSectionInfo]`) sit in the same composition/dxgkrnl stealth-I/O lane (source: wiki/sources/descriptions/gmh5225__NullDriverCheat.md); C++ KM R/W drivers with dxgkrnl hook context such as [[rigel-driver]] (Lynnette177; module-base/export lookup, protected-region writes, mapper-based load; README `[NtGdiDdDDINetDispGetNextChunkInfo]`; driver-assisted memory access / AC bypass research) extend that lane (source: wiki/sources/descriptions/Lynnette177__Rigel-Driver.md); dxgkrnl export hooks on `NtDxgkGetTrackedWorkloadStatistics` such as [[kernel-cheat-for-directx3d]] (gmh5225; jump-stub hijack; `NULL_MEMORY` command dispatcher via win32u; KM R/W + win32k GDI box draw; README `[NtDxgkGetTrackedWorkloadStatistics]`) extend that graphics-syscall covert-comms lane (source: wiki/sources/descriptions/gmh5225__Kernel-Cheat-for-directx3D.md); tutorial split driver+client samples such as [[nullhook]] (NullTerminatorr; C/C++ kernel driver + userland client; memory/hook workflows; external manual-map oriented; educational kernel-assisted cheat development; README `[NtDxgkGetTrackedWorkloadStatistics]`) sit in the same lane (source: wiki/sources/descriptions/NullTerminatorr__NullHook.md); named-event channels such as [[evcommunication]] (`Zw*Event` + `NtTokenManager` hook; `MmCopyVirtualMemory` R/W) avoid monitored IOCTL surfaces; WNF state-name channels such as [[wnf-driver-meme]] (zensenzay; C kernel + C++ client; `WnfNotify` registry discovery; PID memory R/W + ObRegisterCallbacks handle stripping; no device path/IOCTL; game-security / AC / RE research) (source: wiki/sources/descriptions/zensenzay__wnf-driver-meme.md); feature-rich cheat-driver skeletons such as [[driver-kaldereta]] (gmh5225; unsigned KM driver + UM sample; `KALDERETA_MEMORY` via hooked Win32 `NtTokenManagerGetAnalogExclusiveTokenEvent`; process/module lookup, VM alloc/protect, R/W, input sim, pattern scan, manual DLL map; README `[NtTokenManagerGetAnalogExclusiveTokenEvent]`) sit in the same lane (source: wiki/sources/descriptions/gmh5225__Driver-kaldereta.md); shared-memory payload channels such as [[kernel-payload-comms]] (gmh5225; cheat / driver communication) sit in the same lane; `\Driver\PEAUTH` `IRP_MJ_FLUSH_BUFFERS` hijack channels such as [[shared-flushfilebuffers-communication]] (UCFoxi; upstream C++ KM+UM sample; shared buffer + `FlushFileBuffers`-triggered `IRP_MJ_FLUSH_BUFFERS` hook; no persistent worker thread; stealth driver comm; README `[FlushFileBuffers]`) (source: wiki/sources/descriptions/UCFoxi__Shared-FlushFileBuffers-Communication.md); extended fork [[ucfoxi-shared-flushfilebuffers-communication-update]] (registry-seeded shared buffer + `MmCopyVirtualMemory` `REQUEST_DATA`; gmh5225) sit in the same lane; job-object query channels such as [[job-communication]] (`NtQueryInformationJobObject` + `JobObjectReserved17Information`; job silo `ServerSiloGlobals` → `SILO_USER_SHARED_DATA`; gmh5225) study undocumented Ring0↔Ring3 paths without device IOCTLs (source: wiki/sources/descriptions/gmh5225__job_communication.md); system-colors API channels such as [[read-write-driver]] (`ntUserSetSysColors`; Win11 `10.0.22000.376` hardcoded addrs) sit in the same lane; license-value API channels such as [[custom-data-ptr-swap-sample]] (`NtQueryLicenseValue`; C++ driver development; cheat / driver communication; gmh5225) sit in the same lane; visual-mapping API channels such as [[eac-bypass-1]] (`NtMapVisualRelativePoints`; C++ driver development; cheat / driver communication; gmh5225) sit in the same win32k stealth-I/O lane (source: wiki/sources/descriptions/gmh5225__eac-bypass-1.md); HalDispatchTable + `NtQueryIntervalProfile` EAC-state toggles such as [[eac-injector-driver]] (gmh5225; manual-map KM driver; suspend/resume `EasyAntiCheat.sys` threads; temporary object-callback disable; UM shellcode stub + DLL-load workflow; cheat / [NtQueryIntervalProfile]) sit in the same HalDispatchTable stealth-I/O lane (source: wiki/sources/descriptions/gmh5225__Eac-Injector-Driver.md); EAC driver-scan evasion samples such as [[eac-driver-ud-for-now]] (gmh5225; cross-process memory R/W; stealth KM↔UM channel avoiding known EAC kernel-cheat detection vectors; README `[Sample]`) sit in the same stealth driver + [[easy-anti-cheat]] evasion lane (source: wiki/sources/descriptions/gmh5225__EAC-Driver-UD-for-now.md); auxiliary-counter API channels such as [[poseidon]] (`NtConvertBetweenAuxiliaryCounterAndPerformanceCounter`; BE/EAC detection notes); [[dataptrhooks]] (0mWindyBug; C/C++ kernel PoC; `.data` pointer hooks instead of IOCTL; syscall-reachable targets incl. `NtConvertBetweenAuxiliaryCounterAndPerformanceCounter` + code-integrity query flows; CFG-artifact notes for indirect call-site discovery; mapped-driver stealth comm / detection tradeoffs; README `[NtConvertBetweenAuxiliaryCounterAndPerformanceCounter]`) (source: wiki/sources/descriptions/0mWindyBug__DataptrHooks.md) and [[r69-driver]] (`NtQueryAuxiliaryCounterFrequency` via HalPrivateDispatchTable hooks; CR3-backed phys R/W without IOCTL/device objects; gmh5225) (source: wiki/sources/descriptions/gmh5225__r69-driver.md) and [[roak]] (KeServiceDescriptorTable; HAL timer-query hooks + packet-based KM R/W dispatch; kernel offset resolution; README `[NtQueryAuxiliaryCounterFrequency]`) (source: wiki/sources/descriptions/KeServiceDescriptorTable__roak.md) sit in the same lane; leaked Interep cheat-driver samples such as [[interep-driver-leak]] (gmh5225; covert process memory R/W via `NtGdiPolyPolyDraw` win32k GDI channel; README `[NtGdiPolyPolyDraw]`; anti-cheat driver-detection evasion) (source: wiki/sources/descriptions/gmh5225__Interep-Driver-Leak.md) sit in the same lane; data-pointer comm drivers such as [[comm-data-ptr-driver]] (gmh5225; shared data-ptr exchange for KM↔UM memory R/W via `NtGdiPolyPolyDraw`; avoids IOCTL telemetry; README `[NtGdiPolyPolyDraw]`) (source: wiki/sources/descriptions/gmh5225__Comm-data-ptr-driver.md) extend that GDI syscall lane; EAC/BE-oriented win32k hook comm frameworks such as [[kernel-eac-be-comm]] (JGonz1337; C++ kernel driver + user client; hooked win32k function pointer routes custom request structures + XOR-obfuscated strings + compact control protocol; process/module lookup, memory R/W, alloc/free/protect; anti-cheat bypass + game memory tooling research; README `[NtGdiPolyPolyDraw]`) (source: wiki/sources/descriptions/JGonz1337__kernel-eac-be-comm.md); [[ntuserupdatewindowtrackinginfo]] (D3DXVECTOR2; win32k function-pointer hook on **NtUserUpdateWindowTrackingInfo** syscall path; covert KM↔UM comm with process memory R/W, pattern scan, allocation, and pointer swap via custom request codes; user-mode client initializes syscall stub; cheat / AC evasion research at kernel boundary; README `[NtUserUpdateWindowTrackingInfo]`) (source: wiki/sources/descriptions/D3DXVECTOR2__NtUserUpdateWindowTrackingInfo.md); [[ucmiraka-valorant-external]] (Chase1803; C++ PoC external framework; kernel driver hooks win32k **NtUserGetPointerProprietaryId** for custom request packets—process memory R/W and PML4-related retrieval; user client reads Valorant UE pointers UWorld/ULevel/GameState; driver comm + external data extraction / AC research; cheat / game:valorant [External]; README `[NtUserGetPointerProprietaryId]`) (source: wiki/sources/descriptions/Chase1803__UCMiraka-ValorantExternal.md) sit in the same lane; swap-based page-memory covert channels such as [[comm-neko-swap]] (gmh5225; kernel driver; memory page swapping for stealthy KM↔UM data exchange via Win32kApiSetTable; avoids IOCTL telemetry; README `[Win32kApiSetTable]`) (source: wiki/sources/descriptions/gmh5225__Comm-NekoSwap.md) extend that win32k stealth-I/O lane; DComposition child-root-visual pointer-swap PoCs such as [[comm-data-pointer-swap]] (gmh5225; pattern-scan win32kbase.sys; resolve target qword pointer; explorer.exe attach; `InterlockedExchangePointer` replaces internal data pointer with custom handler; user-mode triggers via `NtDCompositionSetChildRootVisual` from win32u.dll; compact GUI-syscall covert-comms PoC—not a full framework; README `[NtDCompositionSetChildRootVisual]`) (source: wiki/sources/descriptions/gmh5225__Comm-Data-Pointer-Swap.md) extend that lane; window-handle hijack drivers such as [[window-hijack]] (thread-context / window-object KM↔UM channel) sit in the same stealth-I/O lane; window-hide driver samples such as [[windowprotect]] (gmh5225; C/C++; driver development / hooking; cheat / hide) extend that win32k window-stealth lane (source: wiki/sources/descriptions/gmh5225__WindowProtect.md); alignment-abuse driver/hook samples such as [[owned-alignment]] target cheat / HWID Ring0 surfaces. (source: wiki/sources/descriptions/zoand__BOOM.md) (source: wiki/sources/descriptions/xPasters__.data-ptr-swap.md) (source: wiki/sources/descriptions/oakboat__DataPtrHookWin11.md) (source: wiki/sources/descriptions/muturikaranja__AfdIrpCallDispatch.md) (source: wiki/sources/descriptions/isoadam__gina_public.md) (source: wiki/sources/descriptions/wbaby__DoubleCallBack.md) (source: wiki/sources/descriptions/weak1337__EvCommunication.md) (source: wiki/sources/descriptions/gmh5225__kernel_payload_comms.md) (source: wiki/sources/descriptions/ryan-weil__ReadWriteDriver.md) (source: wiki/sources/descriptions/paradoxwastaken__Poseidon.md) (source: wiki/sources/descriptions/0mWindyBug__DataptrHooks.md) (source: wiki/sources/descriptions/thesecretclub__window_hijack.md) (source: wiki/sources/descriptions/vmcall__owned_alignment.md) (source: wiki/sources/descriptions/gmh5225__custom_data_ptr_swap_sample.md) (source: wiki/sources/descriptions/gmh5225__UCFoxi-Shared-FlushFileBuffers-Communication-Update.md) Title-specific Apex Legends KM↔UM communication samples such as [[apex-apex-cheese-test]] (gmh5225; C/C++; kernel–usermode communication copied from UnknownCheats; anti-cheat research / driver development; cheat / game:apex legends) sit in the same covert channel lane. (source: wiki/sources/descriptions/gmh5225__Apex-ApexCheeseTest.md) Educational Apex Legends external tutorial codebases with kernel-hijack memory access such as [[nullptr-apex-external]] (M1fisto; C++; kernel hijacking + cross-process game memory R/W + SDK entity handling; user-mode visualization/control; external cheat architecture + AC detection challenges; cheat / game:apex legends [External]) sit beside [[apex-legends-esp]] in the learner lane. (source: wiki/sources/descriptions/M1fisto__nullptr-apex-external.md) - **Keyboard IRP filter / keylog research:** educational samples such as [[keyboardkit]] intercept keyboard IRPs in a filter driver, exfiltrate via UDP usermode, and demonstrate ExplorerFrame DLL-hijack persistence (offensive + defensive IRP-hook analysis). (source: wiki/sources/descriptions/wesmar__KeyboardKit.md) Defensive win32k hotkey-table scanners such as [[hotkeybased-keylogger-detector]] (AsuNa-jp; KMDF driver; resolves win32kfull global hotkey table; flags suspicious `RegisterHotKey` abuse; endpoint security testing; README Detect RegisterHotKey API) complement IRP-hook analysis with global-hotkey registration telemetry. (source: wiki/sources/descriptions/AsuNa-jp__HotkeybasedKeyloggerDetector.md) - **IRP dispatch-table monitoring:** frameworks such as [[cfb]] (Canadian Furious Beaver; filter driver hooks target-driver IRP dispatch tables; logs IRP parameters, buffers, and return values via C driver + Python client; real-time IOCTL interface RE and fuzzing) (source: wiki/sources/descriptions/hugsy__CFB.md) and [[drvtrace]] (eversinc33; filter driver attaches to specific targets; logs IRP major/minor codes, buffer contents, and completion status; runtime driver-communication tracing for IOCTL/device-protocol RE) (source: wiki/sources/descriptions/eversinc33__drvtrace.md); kernel IOCTL hook/dump drivers such as [[ioctldump]] (Kharos102; WDK driver + client; hooks target device drivers; records IOCTL code, transport path type, buffer sizes, and deduplicated input buffer contents; target device selection + structured log output; proprietary driver / AC interface RE; README [Monitor IRP]) (source: wiki/sources/descriptions/Kharos102__IOCTLDump.md); user-mode IOCTL repeaters such as [[ioctlpus]] (VoidSec; C# WinForms GUI + CLI; craft/replay/save/edit DeviceIoControl with arbitrary input/output buffers; repeater-style driver interface auditing and fuzzing prep) (source: wiki/sources/descriptions/VoidSec__ioctlpus.md) and [[ioctl-helper]] (RomanRybachek; C++/Qt Widgets GUI; integrated hex editor; multi-handle DeviceIoControl with configurable control codes and buffer sizes; driver reversing and kernel communication testing) (source: wiki/sources/descriptions/RomanRybachek__ioctl_helper.md); Application Verifier DynFault provider [[vfdynf]] (jxy-s; stack-aware fault injection via `vfdynf.dll`; systematic low-resource failure simulation and OS API fuzzing; alternative to randomized LowRes) supports Windows robustness and vulnerability research on resource-access paths (source: wiki/sources/descriptions/jxy-s__vfdynf.md) - **KM↔UM IPC learning examples:** educational C/C++ sample collection [[km-um-communication]] (adspro15; multiple driver↔usermode IPC and synchronization patterns—request dispatch, event coordination, controlled cross-boundary data exchange in test projects; RE / game-security KM↔UM fundamentals) complements runtime tracing when learning driver↔usermode boundaries. (source: wiki/sources/descriptions/adspro15__km-um-communication.md) Educational Apex Legends shared-memory external samples such as [[r5apex-usermode]] (3nolan5; C++ user-mode external framework; shared-memory IPC with mapped kernel driver for cross-process R/W; minimal glow/highlight baseline for external cheat architecture study; cheat / game:apex legends [External]) extend that lane beside hybrid UM+KM Apex frameworks such as [[uc-apex-remastered]]. (source: wiki/sources/descriptions/3nolan5__R5Apex-UserMode.md) Windows API call obfuscation framework [[apicallproxy]] (MahmoudZohdy; C/C++; routes file/process/memory/registry/network operations through kernel-driver IOCTL handlers instead of direct usermode APIs; sample clients for APC injection, driver load, and socket comms; API monitoring evasion + behavioral-analysis hardening research; README Windows API Call Obfuscation) extends that lane as a structured IOCTL proxy surface. (source: wiki/sources/descriptions/MahmoudZohdy__APICallProxy.md) - **MouClass / kernel mouse input:** research drivers such as [[kernel-mouse]] target mouClass on Windows 10/11 for cheat / triggerbot & aimbot input-path study. (source: wiki/sources/descriptions/vsaint1__kernel-mouse.md) Educational relative-movement samples such as [[kernel-move-mouse]] (BuddyBoi; C++ WDK driver skeleton; OS version checks + per-build offset tables; limited PoC for kernel-level mouse control / driver-dev learning—not evasion-focused) complement MouClass research drivers. (source: wiki/sources/descriptions/BuddyBoi__KernelMoveMouse.md) MouClass **ServiceCallback** injection PoCs such as [[mouseclassservicecallbacktrick]] (ekknod; C; cheat / triggerbot & aimbot; direct MouseClassServiceCallback path) extend that ring-0 mouse-class lane. (source: wiki/sources/descriptions/ekknod__MouseClassServiceCallbackTrick.md) Meme-variant samples such as [[mouseclassservicecallbackmeme]] (ekknod; C; cheat / triggerbot & aimbot; MouseClassServiceCallback meme) sit beside that trick PoC. (source: wiki/sources/descriptions/ekknod__MouseClassServiceCallbackMeme.md) Defensive **MouseClassServiceCallback** hook-detection PoCs such as [[detect-mouseclassservicecallback]] (KANKOSHEV; WDK kernel driver; low-level hook handling to observe/validate mouse callback execution paths; anti-cheat / rootkit input-interception research) complement those offensive injection samples. (source: wiki/sources/descriptions/KANKOSHEV__Detect-MouseClassServiceCallback.md) MouHid **CONNECT_DATA** hook drivers such as [[mouhid-input-hook]] (changeofpace; C; intercept MouHid ClassService callback; filter/modify/inject packets without USB HID stack changes or filter-device objects; PatchGuard-safe PnP-aware unhook; input simulation / AC research) extend that ring-0 mouse-input lane. (source: wiki/sources/descriptions/changeofpace__MouHidInputHook.md) Kernel USB/HID stack tracers such as [[usbmon]] (KelvinMsft; C/C++ WDK driver; hooks IRP and internal IOCTL/URB paths; parses HID reports; custom device-control capture/mapping; traces device data flows into consumer processes; USB/HID input-stack RE and HID attack/detection surface study) extend that lane with upstream USB telemetry rather than MouClass callback interception. (source: wiki/sources/descriptions/KelvinMsft__UsbMon.md) User-mode win32k syscall reference such as [[ntuserinjectmouseinput-syscall]] (gmh5225; **NtUserInjectMouseInput** path; input-injection / triggerbot study) complements MouClass kernel-driver samples. (source: wiki/sources/descriptions/gmh5225__NtUserInjectMouseInput-syscall.md) C++ syscall PoCs such as [[mouse-input-injection]] (Zpes; custom structures + movement/click interface; M3351AN; header-only **`mouse_event`-like** wrappers; alternative to `SendInput`; input-path / automation research) extend that user-mode win32k lane. (source: wiki/sources/descriptions/Zpes__mouse-input-injection.md) (source: wiki/sources/descriptions/M3351AN__mouse_input_injection.md) Ring-3 **SetWindowHookEx** preinjected-DLL research such as [[setwindowhookex]] (ekknod; C; hooking; Some Tricks / Windows Ring3) sits in the adjacent user-mode GUI-subsystem hook lane beside [[setwindowshookex-injector]]. (source: wiki/sources/descriptions/ekknod__SetWindowHookEx.md) Combined kernel keyboard injection + WSK socket PoCs such as [[karlann]] (`Kbd.c` simulation; `Wsk.c` + `libwsk`; cheat / Keyboard) sit in the same ring-0 input + covert-network lane. (source: wiki/sources/descriptions/hkx3upper__Karlann.md) Keyboard+mouse class-service injection research such as [[directinput]] (adspro15; WDK driver + UM companion; stack discovery, service-callback capture, low-level kbd/mou injection without `SendInput`; game automation / AC input-path study) extends that ring-0 input lane. (source: wiki/sources/descriptions/adspro15__DirectInput.md) CS:GO kernel driver + OpenGL samples such as [[ec]] (ekknod; C/C++; kernel-level work / driver development / OpenGL; cheat / game:csgo) complement that input-path lane; related [[ec-pro-lan]] targets FACEIT AC with constrained lab hardware. (source: wiki/sources/descriptions/ekknod__EC.md) Full-game CS 1.6 kernel driver samples such as [[zodiak]] (3a1; C/assembly; kernel GDI ESP rendering, MouHID ClassService callback aimbot injection, automatic offset detection, thread context spoofing, compact single-thread execution; low-trace kernel cheat engineering study; cheat / game:cs1.6 [Fastcup Full Kernel Driver Cheat]) combine the MouHid and kernel-GDI lanes in one end-to-end title. (source: wiki/sources/descriptions/3a1__Zodiak.md) - **Kernel-mode sockets (WSK):** BSD-style wrappers such as [[ksocket]] expose TCP/UDP from ring 0 via Windows Sockets Kernel with no user-mode component—covert kernel network-channel research. (source: wiki/sources/descriptions/wbenny__KSOCKET.md) Socket-style WSK libraries such as [[libwsk]] (MiroKaku; C/C++; NuGet/MSBuild; WDK/VS driver workflows; connect/send/recv + address helpers; lower-friction kernel network I/O for driver dev and security research; Kernel-Mode Winsock library) complement raw WSK integration beside [[ksocket]]. (source: wiki/sources/descriptions/MiroKaku__libwsk.md) Socket-backed protected-process memory R/W drivers such as [[rw-socket-driver]] (adrianyy; C/C++; kernel socket command channel; manual-map oriented; external memory control without in-process hooks; cheat development / AC robustness research) extend that lane beyond raw WSK transport. (source: wiki/sources/descriptions/adrianyy__rw_socket_driver.md) - **WFP packet diversion:** user-mode libraries backed by signed kernel drivers such as [[divert]] (WinDivert; basil00; WFP layer filters; real-time intercept/modify/drop/inject from user mode; firewall/NAT/analyzer/tunnel tooling) illustrate legitimate WFP hooking beside exploit lanes like [[360wfp-exploit]]. (source: wiki/sources/descriptions/basil00__Divert.md) WFP callout-based traffic shapers such as [[win-shaper]] (WPO-Foundation; kernel driver + CLI/GUI; inject latency, bandwidth limits, packet loss, queue sizing for inbound/outbound traffic; Game Testing / adverse network emulation for games and network-sensitive software) extend that lane for controlled network-condition testing. (source: wiki/sources/descriptions/WPO-Foundation__win-shaper.md) - **System / hidden threads:** hidden module/DLL detectors such as [[hidden-module-detector]] (mq1n; C/C++; Detection:Hide) and kernel-level DLL thread injection detectors such as [[dll-thread-injection-detector]] (mq1n; C/C++; Detection:Injection) and defensive load-image stack-trace validators such as [[driver-watchowl]] (gmh5225; `PsSetLoadImageNotifyRoutine` + thread notify; expected `NtMapViewOfSection`/`RtlUserThreadStart` frames from `csrss.exe`; flags non-legitimate module text origins; README `[ImageNotify+Stack Trace]`) (source: wiki/sources/descriptions/gmh5225__Driver-WatchOwl.md) and load-image notify callback hygiene utilities such as [[ps-image-notify-routine-spam-filter]] (Staatsgeheim; C x64 driver; `RtlWalkFrameChain` stack walking filters noisy `PsImageNotifyRoutine` events; kernel monitoring / AC telemetry / cleaner driver-side analysis; README ImageNotify Callback With RtlWalkFrameChain) (source: wiki/sources/descriptions/Staatsgeheim__PsImageNotifyRoutineSpamFilter.md) complement thread-based hide scans; NLS registry code-page redirection PoCs such as [[nls-code-injection-through-registry]] (gmh5225; modify NLS registry keys → custom code-page translation DLL load during early NLS subsystem init; persistence / injection research) load code before many standard injectors run. (source: wiki/sources/descriptions/gmh5225__NlsCodeInjectionThroughRegistry.md) detectors such as [[system-thread-finder]] enumerate threads (`NtQuerySystemInformation`) and flag start addresses outside loaded driver images (BE-style manual-map thread heuristics). (source: wiki/sources/descriptions/mq1n__HiddenModuleDetector.md) (source: wiki/sources/descriptions/mq1n__DLLThreadInjectionDetector.md) (source: wiki/sources/descriptions/weak1337__SystemThreadFinder.md) [[stealth-sytem-thread-finder-be]] (gmh5225) extends that lane with PspCidTable walks, scheduler queue scans, and thread-list cross-reference to find stealth system threads from manually mapped drivers that [[battleye]] misses. (source: wiki/sources/descriptions/gmh5225__StealthSytemThreadFinderBE.md) KTHREAD field-tamper detection PoCs such as [[hidden-thread-finder]] (gmh5225; APC vs NMI callback stack/metadata recovery after clearing `SystemThread`/`ApcQueueable`/`StackBase`/`InitialStack`; Win10 20H2 layout; experimental hidden-thread detector) (source: wiki/sources/descriptions/gmh5225__Hidden-Thread-Finder.md) KPRCB-based hidden-thread detection PoCs such as [[detect-hiddenthread-via-kprcb]] (KANKOSHEV; walks thread information through KPRCB-related structures; verifies thread presence with thread lookup checks; Visual Studio kernel driver; anti-cheat integrity monitoring / low-level forensic research) (source: wiki/sources/descriptions/KANKOSHEV__Detect-HiddenThread-via-KPRCB.md) Multi-method hidden-thread/rootkit scanners such as [[unkover]] (eversinc33; scheduler lists + PspCidTable + stack scanning cross-ref; flags threads hidden from standard API enumeration; NMI/APC mapped-driver artifact detection; anti-cheat / kernel forensics) (source: wiki/sources/descriptions/eversinc33__unKover.md); multi-signal mapped-driver detector [[nomad]] (Rwkeith; thread stack walk + entry-point validation, big-pool abnormal refs, IOCTL hook signals; C++ WDK low-level telemetry; README Mapped Driver) (source: wiki/sources/descriptions/Rwkeith__Nomad.md) Cross-platform Rust live injection scanners such as [[ghost]] (RWX/shellcode/hooks/hollowing/thread checks; CLI/TUI; Windows/Linux/macOS) complement kernel thread-injection detectors for endpoint visibility. (source: wiki/sources/descriptions/pandaadir05__ghost.md) PoCs such as [[zero-thread-kernel]] evade that lane by running via existing contexts / timers instead of new system threads. (source: wiki/sources/descriptions/zer0condition__ZeroThreadKernel.md) [[covert-thread]] (brew02; transparent system threads nearly invisible to introspection via page-table module removal, custom address space + IDT, NMI-blocked per-thread inspection, direct function execution from driver) studies that offensive lane. (source: wiki/sources/descriptions/brew02__CovertThread.md) Concealed thread-start PoCs such as [[driver-hide-kernel-thread-iocancelirp]] (gmh5225; IRP + cancel routine, start thread at `IoCancelIrp`, payload via cancellation path; context via `UserBuffer`/`MdlAddress`; notes `IoCancelIrp` start checks and APC stack walks; README `[Hide Kernel Thread]`) (source: wiki/sources/descriptions/gmh5225__Driver-HideKernelThread-IoCancelIrp.md) Kernel thread-hiding stealth PoCs such as [[diglett]] (Rwkeith; hide system threads + alter thread entry-address visibility; driver + client; anti-cheat evasion / defender blind-spot study; README `[Hide Kernel Thread]`) (source: wiki/sources/descriptions/Rwkeith__Diglett.md) Offensive PspCidTable / handle-table hide samples such as [[driver-systemthread-from-pspcidtable-src]] (gmh5225; `ExRemoveHandleTable` + PspCidTable handle destruction + CID-field zeroing; build-specific EPROCESS/ETHREAD offsets; README `[Hide Process/Thread/Handle]`) target process/thread/handle visibility instead. (source: wiki/sources/descriptions/gmh5225__Driver-Systemthread-from-PspCidTable-src.md) Thread sleep-emulation / context-manipulation PoCs such as [[cheat-attack-thread-slemu]] (gmh5225; Heartbeat Testing) hide cheat worker threads from AC system-thread scans via altered scheduling state. (source: wiki/sources/descriptions/gmh5225__cheat-attack-thread-slemu.md) Multi-telemetry AC research drivers such as [[kernel-anti-cheat]] (gmh5225; `HalSendNMI`/`RtlCaptureStackBackTrace` NMI stack walks + system-thread start-address scans; README `[NMI]`) sit on the defensive side of that thread/stack forensics lane. (source: wiki/sources/descriptions/gmh5225__Kernel_Anti-Cheat.md) Kernel AC simulation driver [[anti-cheat-emulator]] (ApexLegendsUC; stacks system-thread, stack-trace, BigPool, PiDDB, dispatch-table, and physical-memory handle scans with hypervisor/mapping checks for telemetry-pipeline study) complements that lane. (source: wiki/sources/descriptions/ApexLegendsUC__anti-cheat-emulator.md) Behavior-based kernel telemetry platform [[peacemaker]] (D4stiny; process creation, image load, remote thread, hidden code execution, suspicious FS/registry ops with stack traces; driver + CLI + Qt GUI; defensive anti-malware / AC lab research) extends that defensive thread/stack forensics lane. (source: wiki/sources/descriptions/D4stiny__PeaceMaker.md) - **Hidden process detection:** kernel PoCs such as [[rootkit-2]] (gmh5225; attach `csrss.exe`, pattern-scan `CsrExecServerThread` in `csrsrv.dll` for the `CSR_PROCESS` list head, walk linked list → EPROCESS/PID/image name; secondary enumeration exposing processes hidden from standard API views) (source: wiki/sources/descriptions/gmh5225__Rootkit-2.md) complement offline RAM forensics [[volatility]] / [[volatility3]] (`psscan` vs `pslist`) and offensive hide samples such as [[blanket]] and configurable multi-artifact hide frameworks such as [[hidden]] (JKornev; WDK kernel driver + user-mode CLI/library; rules hide files/directories/registry keys/processes + protect chosen processes from interference; reverse-engineering lab / controlled environment masking) (source: wiki/sources/descriptions/JKornev__hidden.md); Linux eBPF **getdents-flow timing-anomaly** research such as [[rootkit-detection-ebpf-time-trace]] (ait-aecid; fine-grained kernel function timing via eBPF; file-hiding rootkit detection; Python experiment orchestration + semi-supervised anomaly scoring) (source: wiki/sources/descriptions/ait-aecid__rootkit-detection-ebpf-time-trace.md); multi-AC kernel drivers such as [[battleye-vac-eac-kernel-bypass]] (daswareinfach; FSFilter/registry filter + process notify hide + IOCTL cross-process R/W; FsFilter Testing; [[battleye]]/[[easy-anti-cheat]]/VAC bypass research) (source: wiki/sources/descriptions/daswareinfach__Battleye-VAC-EAC-Kernel-Bypass.md); VAC-specific external-scanner bypass via [[vac-bypass-kernel]] (crvvdev; kernel-mode counter to `NtReadVirtualMemory`-style cross-process reads; explore anticheat:vac) (source: wiki/sources/descriptions/crvvdev__vac-bypass-kernel.md). - **OS LPE / sandbox escape:** historical CVE-indexed LPE PoC corpus such as [[localroot-all-cve]] (Snoopy-Sec; year/CVE-organized local privilege escalation samples—mostly C with shell/Python scripts and per-vulnerability notes; browse kernel-era exploit code and recreate older research in controlled labs; security education / exploit-development study / vulnerability timeline reference; README [Root CVE]) complements single-CVE PoCs in this lane. (source: wiki/sources/descriptions/Snoopy-Sec__Localroot-ALL-CVE.md) First-party Windows LPE PoCs such as [[cve-2026-40369-exploit]] abuse `NtQuerySystemInformation` class 253 for arbitrary kernel address increment on Win11 24H2–25H2 (Chrome-sandbox reachable). (source: wiki/sources/descriptions/orinimron123__CVE-2026-40369-EXPLOIT.md) Hyper-V virtualization-stack heap overflow LPE such as [[cve-2025-21333]] (`vskrnlintvsp.sys` integer truncation → IoRing pool spray / pipe-attribute arbitrary R/W). (source: wiki/sources/descriptions/nu1lptr0__CVE-2025-21333.md) Alternate [[cve-2025-21333-poc]] (gmh5225; Win11 23H2; `vkrnlintvsp.sys` heap overflow; ITW-exploited). (source: wiki/sources/descriptions/gmh5225__CVE-2025-21333-POC.md) Kernel streaming untrusted-pointer LPE such as [[cve-2024-35250]] (gmh5225; `ks.sys` CWE-822; `KSPROPERTY` requests; Win10/11; Devcore kernel-streaming-proxy research). (source: wiki/sources/descriptions/gmh5225__CVE-2024-35250.md) Client Side Caching improper-address-validation LPE such as [[cve-2024-26229]] (gmh5225; `csc.sys` CWE-781; `METHOD_NEITHER` IOCTL handling; Win11 22H2). (source: wiki/sources/descriptions/gmh5225__CVE-2024-26229.md) Application Identity driver IOCTL LPE such as [[cve-2024-21338]] (gmh5225; `appid.sys`; Win11 22H2 Build 22621; XSS PWN-Day; kernel IOCTL exploitation). (source: wiki/sources/descriptions/gmh5225__CVE-2024-21338.md) Common Log File System driver LPE such as [[cve-2024-49138-poc]] (MrAle98; `CLFS.sys`; C++ Visual Studio solution; kernel R/W primitives + token swap → SYSTEM shell; tested Win11 builds; vulnerability research / patch validation). (source: wiki/sources/descriptions/MrAle98__CVE-2024-49138-POC.md) AMD **`atdcm64a.sys`** arbitrary-pointer-dereference LPE PoC such as [[atdcm64a-lpe]] (MrAle98; C++ Visual Studio solution + PowerShell/batch deployment scripts; lab-oriented driver-interaction exploit template; kernel exploitation / driver security hardening research; README [atdcm64a.sys]). (source: wiki/sources/descriptions/MrAle98__ATDCM64a-LPE.md) Filesystem-helper driver IOCTL improper-access-control LPE such as [[cve-2022-42046]] (gmh5225; `wfshbr64.sys`; IOCTL abuse → SYSTEM). (source: wiki/sources/descriptions/gmh5225__CVE-2022-42046.md) Zemana `amsdk.sys` in-driver `.hook` stub injection such as [[cve-2022-42045]] (gmh5225; IOCTL `0x80002044`/`0x80002014` → plant shellcode in driver image → kernel execution; DSE-bypass research lane). (source: wiki/sources/descriptions/gmh5225__CVE-2022-42045.md) Lenovo `LenovoDiagnosticsDriver.sys` IOCTL-validation LPE such as [[cve-2022-3699]] (gmh5225; improper IOCTL validation → arbitrary kernel memory access → user-mode privilege escalation). (source: wiki/sources/descriptions/gmh5225__CVE-2022-3699.md) Dell **`dbutil_2_3.sys`** signed-driver LPE such as [[cve-2021-21551]] (gmh5225; CVE-2021-21551; arbitrary kernel R/W IOCTLs → SYSTEM token theft via `EPROCESS` walk). (source: wiki/sources/descriptions/gmh5225__CVE-2021-21551.md) - **Driver unit testing:** frameworks such as [[wdutf]] host Microsoft C++ unit tests in user space against kernel-driver code (AC / defensive driver harness lane). (source: wiki/sources/descriptions/wpdk__wdutf.md) C++17 kernel driver protect/obfuscate library [[kernelcloak]] (ck0i; advanced library for protecting/obfuscating kernel drivers; driver development / modding; AC Encrypt Variable / obfuscation-engine research) complements compile-time KM helpers such as [[kli]] in the same driver hardening lane. (source: wiki/sources/descriptions/ck0i__Kernelcloak.md) Runtime zero-IAT kernel API resolver [[noimportz]] (Th3Spl; LSTAR MSR→ntoskrnl locate, `PsLoadedModuleList` export walk; C++17 header for manually mapped/import-free drivers; template calls + hash-map cache; sample KMDF driver; reduces driver IAT visibility to AC scanners). (source: wiki/sources/descriptions/Th3Spl__NoImportz.md) Hash-based ntoskrnl export walker [[zeroimport]] (1hAck-0; C++ runtime import resolve for kernel drivers; hashed export names, no cleartext API strings, optional cache; `MmIsAddressValid`/`PsInitialSystemProcess`-class symbols; import-table stealth for driver dev / static-analysis resistance). (source: wiki/sources/descriptions/1hAck-0__zeroimport.md) Rust kernel driver development framework [[windows-kernel-rs]] (StephanvanSchaik; generated bindings + safer abstractions for IRPs, device I/O, sync primitives, process attach; staged examples + build scaffolding; researchers / systems dev exploring Rust in kernel mode; Writing Windows kernel drivers in Rust) (source: wiki/sources/descriptions/StephanvanSchaik__windows-kernel-rs.md) KMDF starter template [[driver-base]] (SecondNewtonLaw; C++ CMake + FindWDK; driver-entry scaffolding, optional compile-time obfuscation via bundled obfusheader.h; simplifies WDK toolchain across Windows targets; security researchers / low-level driver prototyping baseline) (source: wiki/sources/descriptions/SecondNewtonLaw__DriverBase.md); modern C++ kernel driver framework/template [[kernel-bridge]] (HoShiMin; memory ops, IOCTL, hooks, CPUID/MSR abstractions; Intel VT-x + AMD-V hypervisor-assisted components; debugging / monitoring / AC kernel research) (source: wiki/sources/descriptions/HoShiMin__Kernel-Bridge.md) - **Ricochet AC research:** [[ricochet-disabler]] targets Activision Ricochet kernel-driver and user-mode components to disable or bypass monitoring for Call of Duty anti-cheat architecture research; complements [[ricochet-deobfuscator]] and [[hidden-syscall-monitoring]]. (source: wiki/sources/descriptions/gmh5225__ricochet-disabler.md) Version-specific PatchGuard research (e.g. [[pg1903]] on Win10 1903 via context-page NX manipulation) illustrates how PG bypass studies map to the Demo NX / Cheat PatchGuard README lane. (source: wiki/sources/descriptions/zzhouhe__PG1903.md) Educational demystification material such as [[demystifying-patchguard]] sits in the same lane for RE of [[patchguard]] internals. (source: wiki/sources/descriptions/zer0condition__Demystifying-PatchGuard.md) PG monitoring tooling such as [[sushi]] targets the same cheat / PatchGuard-related area. (source: wiki/sources/descriptions/tandasat__Sushi.md) Multi-method runtime PG + DSE disable tooling such as [[upgdsed]] (hfiref0x; vulnerable signed drivers, CI.dll globals, KPP context patching; Win7–11) spans the same PatchGuard / DSE cheat lane. (source: wiki/sources/descriptions/hfiref0x__UPGDSED.md) Runtime vulnerable-PG exploit PoCs such as [[vulnerablepatchguardexploit]] (gmh5225; C++; disable PatchGuard on runtime) sit in the same lane. (source: wiki/sources/descriptions/gmh5225__VulnerablePatchGuardExploit.md) PatchGuard stress-testing samples such as [[quickpgtrigger]] (gmh5225; C/C++; Anti Cheat Stress Testing) exercise KPP integrity paths under load in that lane. (source: wiki/sources/descriptions/gmh5225__QuickPGTrigger.md) 2023-era [[patchguard-2023]] research (gmh5225; timer verification, context encryption, protected-structure list, recovery routines, trigger mechanisms, bypass study) documents evolving KPP internals for kernel researchers. (source: wiki/sources/descriptions/gmh5225__Patchguard-2023.md) Partial PG disable PoCs such as [[tableflipper]] (emlinhax; C++; builds up to Win11 21H2) sit in the same cheat / PatchGuard-related lane. (source: wiki/sources/descriptions/emlinhax__tableflipper.md) Assembly-hook PG interference PoCs such as [[easy-anti-patchguard]] (armasm; driver + low-level hooks; Win8–Win10; call-chain analysis from kernel debugging) target the same KPP internals / bypass study lane. (source: wiki/sources/descriptions/armasm__EasyAntiPatchGuard.md) Win11 24H2–25H2 runtime PG bypass PoCs such as [[kurasagi]] (NeoMaster831; C/C++ kernel components; [[kdmapper]] manual-map load; CRITICAL_STRUCTURE_CORRUPTION edge-case research; lab-only) extend that lane to recent builds. (source: wiki/sources/descriptions/NeoMaster831__kurasagi.md) Defensive PG-style integrity monitors such as [[patchguard-encryptor-driver]] (AmitMoshel1; C++ kernel driver; KTIMER/KDPC periodic SSDT/IDT/MSR checks plus timer/DPC meta-integrity verification; kernel anti-tamper research; README `[Self-implemented PatchGuard]`) model how periodic structure verification can be implemented outside Microsoft's KPP. (source: wiki/sources/descriptions/AmitMoshel1__PatchGuardEncryptorDriver.md) In-progress dynamic modern-build PG bypass research such as [[patchguardbypass]] (AdamOron; C/C++; planned disable/evade/verify PG state goals) extends that lane for kernel security and anti-cheat analysts. (source: wiki/sources/descriptions/AdamOron__PatchGuardBypass.md) Kernel toolkit [[shark]] (9176324; C/C++/assembly; x86/x64 driver + loader; runtime PatchGuard disable; VS/NMAKE builds; virtualization-assisted loading references; cheat / PatchGuard-related) targets low-level KPP bypass study in the same lane. (source: wiki/sources/descriptions/9176324__Shark.md) ## Related concepts [[kernel-evidence-baseline]] · [[driver-trust-boundaries]] · [[kernel-callbacks]] · [[kernel-pool-scanning]] · [[etw-threat-intelligence]] · [[research-rigor]] · [[boundcallback]] · [[mapped-callback]] · [[callout-poc]] · [[byovd]] · [[physmem-drivers]] · [[windows-kernel-exploits]] · [[exploits]] · [[localroot-all-cve]] · [[trinity]] · [[hacksysextremevulnerabledriver]] · [[smep-bypass]] · [[ven0m-ransomware]] · [[cve-2025-26125]] · [[av-edr-killer]] · [[edr-xdr-av-killer]] · [[watchdog-killer]] · [[terminator]] · [[blackout]] · [[process-killer-byovd]] · [[nsecsoft-byovd]] · [[poison-killer-bof]] · [[killer]] · [[killer-exercice]] · [[pplkiller]] · [[forti-research]] · [[createprocessasppl]] · [[zam64-zemina]] · [[s4killer]] · [[s4mapper]] · [[rtcore64-vulnerability]] · [[razer-rzctl]] · [[cve-2015-2291]] · [[cve-2017-9769]] · [[qiomem]] · [[amd-ryzen-master-driver-v17-exploit]] · [[badrentdrv2]] · [[nvdrv]] · [[360wfp-exploit]] · [[xign-poc-april-2026]] · [[lenovo-cve-2025-8061]] · [[cpuc-dsefix]] · [[cpuz]] · [[ampa-sys-exp]] · [[kvc]] · [[kernel-research-kit]] · [[bootbypass]] · [[openpetya]] · [[bootexecute-edr]] · [[solemn]] · [[pastdse]] · [[dse-hook]] · [[dse-patcher-2]] · [[disabledse]] · [[dsedodge-signed-kernel-driver]] · [[zero-hvci]] · [[magic-signer]] · [[kvcforensic]] · [[windefctl]] · [[defender-control]] · [[disable-windows-defender-]] · [[wdactools]] · [[vaultguard]] · [[hide-file]] · [[hide-driver]] · [[hidedriver]] · [[hide-driver-testing]] · [[drv-hide-and-camouflage]] · [[blanket]] · [[herpaderping]] · [[process-cloning]] · [[keyboardkit]] · [[cfb]] · [[drvtrace]] · [[ioctlpus]] · [[vfdynf]] · [[kernel-mouse]] · [[karlann]] · [[ksocket]] · [[hvci]] · [[cet-research]] · [[cet-win10]] · [[windows-kernel-shadow-stack]] · [[query-shadow-stack]] · [[bugcheck-suppressor]] · [[nomore-bugcheck]] · [[nomore-bugcheck-reloaded]] · [[bugcheckhack]] · [[bad-bugcheck]] · [[bad-bugcheck-old]] · [[kmdfmandelcheck]] · [[detect-tpm-spoofing]] · [[tpm-spoofer]] · [[tpm-mmio]] · [[windbg-scripts]] · [[windbg-cookbook]] · [[twindbg]] · [[swishdbgext]] · [[windows-kernel-debugging-guide]] · [[ida-vmware-windows-gdb]] · [[ida-bochs-windows]] · [[copy-rva]] · [[comon]] · [[dk]] · [[mcp-windbg]] · [[windbg-tool]] · [[windbg-copilot]] · [[windbg-decompile-ext]] · [[kn-live-dbg]] · [[kdbg]] · [[kdbgdecryptor]] · [[nokd]] · [[ntoseye]] · [[koidbg]] · [[kn-diff-pool]] · [[pooldump]] · [[pocsmith]] · [[iida-mcp]] · [[symlink-callback]] · [[patchguard]] · [[pg1903]] · [[upgdsed]] · [[vulnerablepatchguardexploit]] · [[quickpgtrigger]] · [[patchguard-2023]] · [[patchguard-encryptor-driver]] · [[patchguardbypass]] · [[shark]] · [[tableflipper]] · [[easy-anti-patchguard]] · [[kurasagi]] · [[demystifying-patchguard]] · [[sushi]] · [[ntmemory]] · [[cheat-driver]] · [[norsefire]] · [[kernel-csgo]] · [[garhal-csgo]] · [[simple-rust-base]] · [[simple-eft-base]] · [[readphys]] · [[pdb]] · [[diasymbolview]] · [[pdbr]] · [[pdb-rs]] · [[pdblister]] · [[ntkernelwalkerlib]] · [[ntoskrnl-viewer]] · [[ntoskrnlwalker]] · [[kpdb]] · [[ntsleuth]] · [[syscalls-cpp]] · [[inline-syscall]] · [[doom-syscalls]] · [[ebyte-syscalls]] · [[kli]] · [[higu-ntcall]] · [[instrumentation-callback-syscall-logger]] · [[hooking-via-instrumentation-callback]] · [[etwti-syscall-hook]] · [[hidden-syscall-monitoring]] · [[ricochet-disabler]] · [[ricochet-deobfuscator]] · [[anticheat-poc]] · [[umium]] · [[darken-anticheat]] · [[function-collections]] · [[winvisor]] · [[sogen]] · [[emulator]] · [[kace]] · [[holodori-kernel-bypass]] · [[hv]] · [[hypervisor-from-scratch]] · [[ophion]] · [[hypervisor]] · [[minivisorpkg]] · [[hyper-rev]] · [[voyager]] · [[checkhv-um]] · [[hypervisor-detection]] · [[hv-detect]] · [[go-detection-hyper-v]] · [[detection-hyper-v]] · [[vmaware]] · [[ept-hook-detection]] · [[ermsb-meme]] · [[rep-mov-ept-detecc]] · [[vmdtstr]] · [[hvdetecc]] · [[vt-debuuger]] · [[erisdbg]] · [[unreal-vtdbg]] · [[baresvm]] · [[aether-visor]] · [[lsass-extend-mapper]] · [[revert-mapper]] · [[nullmap]] · [[known-driver-mappers]] · [[kdmapper]] · [[kdmapper-rs]] · [[saturn-mapper]] · [[anti-cheat-amateur]] · [[xigmapper]] · [[uefi-bootloader]] · [[efitool]] · [[eficmake]] · [[simpleuefi]] · [[luaboot]] · [[ida-efiutils]] · [[efixplorer]] · [[fiano]] · [[amd-sp-loader]] · [[cmdt]] · [[manipulating-token]] · [[x260-lenovo-opencore]] · [[etw-explorer]] · [[etw-watcher]] · [[dbgviewex]] · [[bamboozledr]] · [[disable-threat-tracing]] · [[tietwagent]] · [[threat-intelligence-consumer]] · [[fibratus]] · [[openprocmon]] · [[readdirectorychanges]] · [[minivers]] · [[wazuh]] · [[openark]] · [[winark]] · [[ksword]] · [[kreclassex]] · [[systeminformer]] · [[document]] · [[winkernel-resources]] · [[nemesis]] · [[ks-dumper]] · [[ksdumper-11]] · [[dioprocess-private]] · [[volatility]] · [[volatility3]] · [[ephemera]] · [[system-thread-finder]] · [[stealth-sytem-thread-finder-be]] · [[hidden-thread-finder]] · [[cve-2026-40369-exploit]] · [[cve-2025-21333]] · [[boom]] · [[driver-read-write]] · [[swap-control-ioctl]] · [[driver-driver-no-image]] · [[data-ptr-swap]] · [[dataptrswap-driver]] · [[comm-data-ptr-driver]] · [[comm-neko-swap]] · [[comm-data-pointer-swap]] · [[dataptrhookwin11]] · [[dataptrhooks]] · [[afd-irp-call-dispatch]] · [[gina-public]] · [[double-callback]] · [[kernel-dwm]] · [[read-write-driver]] · [[window-hijack]] · [[owned-alignment]] · [[apc-research]] · [[stealth-apc-dispatcher]] · [[kernel-special-apc-readprocessmemory]] · [[goodeye]] · [[bedaisy]] · [[injdrv]] · [[kinject]] · [[kernel-dll-injector]] · [[kptnhook]] · [[zero-thread-kernel]] · [[covert-thread]] · [[cheat-attack-thread-slemu]] · [[kernel-codecave-poc]] · [[irql]] · [[pidqserializationwrite-example]] · [[windows-kernel-pagehook]] · [[page-table-hook]] · [[powerhook]] · [[yumekage]] · [[fast-pf-hook]] · [[budget-ept]] · [[hook-kdtrap]] · [[driver-kdtour]] · [[driver-hypercall-page-hook]] · [[hook-hvl-switch-virtual-address-space]] · [[hyperdeceit]] · [[pteditor]] · [[ptview]] · [[page-table-injector]] · [[executor]] · [[wdutf]] · [[driver-base]] · [[ida-kmdf]] · [[driver-buddy-reloaded]] · [[ida-bitfields]] · [[ntrays]] · [[windows-subsystem-linux]] · [[wsl]] · [[wsl2-linux-kernel]] · [[docker-win]] · [[dma]] · [[overviews/anti-cheat]] · [[cve-2025-24990-poc]] ## README map Cheat PatchGuard/DSE/Windows Kernel Explorer/Vulnerable Driver; Anti Cheat Detection:Attach|Hide|Vulnerable Driver|Hacked Hypervisor; `Windows Security Features` (~10: CET/shadow stack, TPM PCR attestation of CPU virt/IOMMU/Secure Boot/VBS/HVCI/DSE/vulnerable-driver blocklist — e.g. [[sewindows]] local PCR replay + remote attestation + [[windows-runtime-attestation-report]] GetRuntimeAttestationReport driver/hotpatch dump) (source: wiki/sources/descriptions/fsquirt__SEWindows.md) (source: wiki/sources/descriptions/CodeMaxx__windows-runtime-attestation-report.md); `Some Tricks` (~118) `> Windows Ring0` (Unity-centric `PiDqSerializationWrite` samples such as [[pidqserializationwrite-example]]) + Ring3 user-space Discord DPI relay [[discord-dpi-bridge]] (ByeDPI SOCKS5 + DoH; avoids WinDivert drivers that break EAC/Denuvo) (source: wiki/sources/descriptions/stuxnet147__PiDqSerializationWrite-Example.md) (source: wiki/sources/descriptions/egeorcun__discord-dpi-bridge.md); adjacent `Windows Emulator` (~7; user-space + WHP trap-driven guests + hybrid semi-emulated/semi-native kernel-driver stacks such as [[kdemu]] (PE load, exception handling, dump integration, anti-detection; rootkit/AC analysis) (source: wiki/sources/descriptions/ShallowFeather__KDemu.md)) and `WSL` (~4; Windows-side stack via [[wsl]] — Lxss Manager, DrvFS, GNS, init/VM infra — plus guest kernel source [[wsl2-linux-kernel]], rolling stable builds via [[wsl2-linux-kernel-rolling]] (Nevuly; CI-driven x86/ARM64 kernel rebuilds + config guidance; reproducible WSL2 guest-kernel workflows for testing/research), and community full-tree references such as [[windows-subsystem-linux]]; WSL2 networking research via [[docker-win]]). (source: wiki/sources/README-categories.md) (source: wiki/sources/descriptions/microsoft__WSL.md) (source: wiki/sources/descriptions/microsoft__WSL2-Linux-Kernel.md) (source: wiki/sources/descriptions/Nevuly__WSL2-Linux-Kernel-Rolling.md) (source: wiki/sources/descriptions/sxlmnwb__windows-subsystem-linux.md) (source: wiki/sources/descriptions/k3v1n1990s__docker-win.md)