dkom.dev

kernel internals · reverse engineering · detection engineering

Field notes on Windows kernel internals, driver reverse engineering, and the detection engineering that comes after. Mostly things I wish I’d found written down when I went looking.

What ends up here: IOCTL dispatch reversing, EDR and anticheat kernel callbacks, process injection primitives, inline and EPT hooking, hypervisor internals (VT-x, EPT, Hyper-V), BYOVD, DSE and code-signing, and the telemetry that catches all of it. Working code and diagrams where they help.

recent posts