Dor00tkit / BamExtensionTableHookLinks

Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
72Updated this week

Alternatives and similar repositories for BamExtensionTableHook

Users that are interested in BamExtensionTableHook are comparing it to the libraries listed below

Sorting: