Skip to content

Research on Windows Kernel Executive Callback Objects

Notifications You must be signed in to change notification settings

hypervisor/ExecutiveCallbackObjects

 
 

Repository files navigation

ExecutiveCallbackObjects

Research on Windows Kernel Executive Callback Objects

OS Version: Windows 10 Pro Insiders Preview 20H1 19008 or later

List of researched callback objects

IoSessionNotifications

LicensingData

LLTDCallbackMapper

LLTDCallbackRspndr

NdisBindUnbind

PowerState

ProcessorAdd

SeImageVerificationDriverInfo

SetSystemState

SetSystemTime

TcpTimerStarvationCallbackTemp

VidPhu

Disclaimer

This investigation is just being held for research purpose, we don't take part nor encourage any illegitimate use of what is explained in this repository. Also if you find any mistakes or different behaviours please feel free to contribute, we would gladly appreciate any contribution.

Acknowledgments

hFiref0x for WinObjEx64

About

Research on Windows Kernel Executive Callback Objects

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • C 85.0%
  • Python 15.0%