github Actively maintained

Dor00tkit/BamExtensionTableHook

Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.

1 awesome list

Quick read

Stars
97
Forks
12
Open issues
0
Commits
2

Activity and growth

Latest capture 2026-07-29 03:08

Stars · last 7 days
No history
Commits · last 7 days
No history
Stars since tracking
-1
Stored snapshots
3

Metadata

Language
C
Default branch
main
Created
2025-07-07
First commit
2025-07-07
Last pushed
2025-07-07
GitHub updated
2026-07-17
Last synced
2026-07-29 03:08
Stack scanned
2026-07-29 03:08
Archived
No

AI development signals

0 paths

Agent instructions and tool configuration found in this repository.

No config files detected.

Growth history

Tracked growth

3 observed captures since 2026-06-24. Charts use measured snapshots only.

Stars from first capture -1

Time horizon

All tracked data

Custom date range

Stars history

Observed snapshots

Commits history

Observed snapshots

Similar repositories

Nearest indexed repositories by embedding similarity.

gmh5225/BYOVD

Some POCs for my BYOVD research and find some vulnerable drivers

0 stars
Rust 1 awesome list

0xJs/BYOVD_EDRKiller

Proof of Concepts code for Bring Your Own Vulnerable Driver techniques

115 stars
C 1 awesome list

hfiref0x/KDU

Kernel Driver Utility

2,673 stars
C 1 awesome list

gmh5225/CVE-2025-21333-POC

Poc exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY

0 stars
1 awesome list