Kernel Detective [portable] ✪

— Outdated by modern standards. Doesn't work on x64 Windows without disabling PatchGuard (requires test signing or boot-time hacks). No longer maintained.

: Scans the SSDT to find modified entries, a common method used by malware to intercept system calls. kernel detective