Kernel Detective [portable] ✪
— Outdated by modern standards. Doesn't work on x64 Windows without disabling PatchGuard (requires test signing or boot-time hacks). No longer maintained.
: Scans the SSDT to find modified entries, a common method used by malware to intercept system calls. kernel detective