Kernel-Process-Hollowing icon indicating copy to clipboard operation
Kernel-Process-Hollowing copied to clipboard

Windows x64 kernel mode rootkit process hollowing POC.

Windows Kernel Mode Process Hollowing

This project is a proof of concept of how the Process Hollowing technique works from the kernel level.

Resources

SSDT Hook

Process Hollowing