The Kernel Shellcode Loader is a tool that uses a custom Windows kernel driver to load and execute Windows kernel shellcode. Debugging malware samples that detonate kernel shellcode can be an efficient way to get around packing or obfuscation and quickly identify the structures, system routines, and processes that a kernel shellcode sample is accessing.
The Terms of Use for this software are subject to the licensing and terms outlined in the OSS repository.
Developer: | FireEye |
Contact: | Issues |
Resources: | FireEye Blog |
Platform: | Windows |