abusing signed pdfwkrnl.sys for kernel function calling from usermode.
Updated 2025-11-24 15:40:28 +08:00
KVC enables unsigned driver loading via DSE bypass (g_CiOptions patch/skci.dll hijack) and PP/PPL manipulation for LSASS memory dumping on modern Windows with HVCI/VBS.
bypass-dse-load-unsigned-driver-windows11
disable-windows-defender-tamper-protection
driver-signature-enforcement-bypass-hvci-windows
dump-lsass-memory-protected-process-light
kernel-driver-stealth-loading
protected-process-light-ppl-wintcb-bypass
secureboot-disable-unsigned-driver-load
unprotect-process-ppl-wintcb
windows-watermark-removal-tool
Updated 2025-11-24 09:38:16 +08:00