> For the complete documentation index, see [llms.txt](https://ppn.snovvcra.sh/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ppn.snovvcra.sh/red-team/dev/kernel-mode.md).

# Kernel Mode

## Lord Of The Ring0

* [Part 1 | Introduction](https://idov31.github.io/2022/07/14/lord-of-the-ring0-p1.html)
* [Part 2 | A tale of routines, IOCTLs and IRPs](https://idov31.github.io/2022/08/04/lord-of-the-ring0-p2.html)
* [Part 3 | Sailing to the land of the user (and debugging the ship)](https://idov31.github.io/2022/10/30/lord-of-the-ring0-p3.html)
* [Part 4 | The call back home](https://idov31.github.io/2023/02/24/lord-of-the-ring0-p4.html)
* [Part 5 | Saruman's Manipulation](https://idov31.github.io/2023/07/19/lord-of-the-ring0-p5.html)
* <https://github.com/Idov31/Nidhogg>

## Rootkits

* <https://github.com/daem0nc0re/VectorKernel>

## Tools

* <https://github.com/lem0nSec/KBlast>

## KKExecDD

* <https://github.com/floesen/KExecDD>
* <https://tierzerosecurity.co.nz/2024/04/29/kexecdd.html>
* <https://github.com/scrt/KexecDDPlus>
