br-sn/CheekyBlinder
Enumerating and removing kernel callbacks using signed vulnerable drivers
A simple 200 LOC kernel driver that displays a bitmap after a BSOD.
Appears on
Quick read
Latest capture 2026-08-29 03:05
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
4 observed captures since 2026-06-24. Observed captures are shown by default.
Stars from first capture 0
Observed captures only
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Enumerating and removing kernel callbacks using signed vulnerable drivers
Kernel Driver Utility
kernel mode anti cheat
HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
A proof of concept demonstrating communication via mapped shared memory structures between a user-mode process and a kernel-mode payload on Windows 10 20H2.
The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.