br-sn/CheekyBlinder
Enumerating and removing kernel callbacks using signed vulnerable drivers
No description.
Appears on
Quick read
Latest capture 2026-08-30 03:06
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
4 observed captures since 2026-06-24. Observed captures are shown by default.
Stars from first capture 0
Observed captures only
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Enumerating and removing kernel callbacks using signed vulnerable drivers
Research on Windows Kernel Executive Callback Objects
Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
Incident Response & Digital Forensics Debugging Extension
Alternative Shellcode Execution Via Callbacks
A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.