Dor00tkit/BamExtensionTableHook
Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
Repository profile
Research on Windows Kernel Executive Callback Objects
Repository updates
Get generated 0xcpu/ExecutiveCallbackObjects development summaries by email, or follow the weekly and monthly RSS feeds.
Sign in to subscribe by email. RSS feeds are public.
Sign in to subscribeTracked growth, recent movement, and commit velocity from stored repository snapshots.
Latest capture 2026-06-24 13:00
1 capture since 2026-06-24
Stars from baseline 0
All tracked data
Frameworks, package managers, ecosystems, and dependency manifests found during catalog scans.
Scanned 2026-06-24 13:00
EnlightenmentState/EnlightenmentState.sln
dotnet ecosystem,
0 dependencies
Loader/Loader.sln
dotnet ecosystem,
0 dependencies
Phase1InitComplete/Phase1InitComplete.sln
dotnet ecosystem,
0 dependencies
TcpConnectionCallbackTemp/TcpConnectionCallbackTemp.sln
dotnet ecosystem,
0 dependencies
WdProcessNotificationCallback/WdProcessNotificationCallback.sln
dotnet ecosystem,
0 dependencies
542875F90F9B47F497B64BA219CACF69/PGCbUtil/PgCbUtil.sln
dotnet ecosystem,
0 dependencies
Searchable topics, generated tags, and stack labels that explain where this repository fits.
Agent instructions and tool configuration paths found in the repository tree.
Nearest indexed repositories by embedding similarity.
Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
Windows Object Explorer 64-bit
Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999
Windows Kernel Programming Experiments
No description.
Enumerating and removing kernel callbacks using signed vulnerable drivers