aftermathlabs/msrexec
Elevate arbitrary MSR writes to kernel execution.
Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999
Appears on
Quick read
Latest capture 2026-08-29 03:04
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
4 observed captures since 2026-06-24. Observed captures are shown by default.
Stars from first capture +1
Observed captures only
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Elevate arbitrary MSR writes to kernel execution.
Elevate arbitrary MSR writes to kernel execution.
Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
Poc exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
ntoskrnl .data hooks for UM-KM communication
Hook system calls, context switches, page faults and more.