github Actively maintained

Deputation/instrumentation_callbacks

A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.

1 awesome list

Quick read

Stars
160
Forks
28
Open issues
0
Commits
12

Activity and growth

Latest capture 2026-07-29 03:08

Stars · last 7 days
No history
Commits · last 7 days
No history
Stars since tracking
-3
Stored snapshots
3

Metadata

Language
C++
License
MIT
Default branch
master
Created
2021-09-21
First commit
2021-09-21
Last pushed
2021-11-14
GitHub updated
2026-07-09
Last synced
2026-07-29 03:08
Stack scanned
2026-07-29 03:08
Archived
No

AI development signals

0 paths

Agent instructions and tool configuration found in this repository.

No config files detected.

Growth history

Tracked growth

3 observed captures since 2026-06-24. Charts use measured snapshots only.

Stars from first capture -3

Time horizon

All tracked data

Custom date range

Stars history

Observed snapshots

Commits history

Observed snapshots

Similar repositories

Nearest indexed repositories by embedding similarity.

br-sn/CheekyBlinder

Enumerating and removing kernel callbacks using signed vulnerable drivers

594 stars
C++ 1 awesome list

0xcpu/WinAltSyscallHandler

Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999

244 stars
C 1 awesome list

Dor00tkit/BamExtensionTableHook

Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.

97 stars
C 1 awesome list

gmh5225/Comm-kernel_payload_comms

A proof of concept demonstrating communication via mapped shared memory structures between a user-mode process and a kernel-mode payload on Windows 10 20H2.

0 stars
1 awesome list