br-sn/CheekyBlinder
Enumerating and removing kernel callbacks using signed vulnerable drivers
No description.
Appears on
Quick read
Latest capture 2026-07-29 03:07
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
3 observed captures since 2026-06-24. Charts use measured snapshots only.
Stars from first capture 0
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Enumerating and removing kernel callbacks using signed vulnerable drivers
Research on Windows Kernel Executive Callback Objects
Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
Incident Response & Digital Forensics Debugging Extension
Alternative Shellcode Execution Via Callbacks
A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.