0xcpu/ExecutiveCallbackObjects
Research on Windows Kernel Executive Callback Objects
A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.
Appears on
Quick read
Latest capture 2026-07-29 03:08
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
3 observed captures since 2026-06-24. Charts use measured snapshots only.
Stars from first capture -3
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Research on Windows Kernel Executive Callback Objects
Enumerating and removing kernel callbacks using signed vulnerable drivers
Alternative Shellcode Execution Via Callbacks
Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999
Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
A proof of concept demonstrating communication via mapped shared memory structures between a user-mode process and a kernel-mode payload on Windows 10 20H2.