discovered 03 Aug 2026
Hells-Hollow
→ View on GitHubHell's Hollow is a rootkit technique specifically designed for Windows 11 that enables effective SSDT hooking by exploiting an undocumented Alternate Syscall handler mechanism. This tool allows users to manipulate system calls at the kernel level, enabling alteration of return values and system call arguments while bypassing existing defense mechanisms like HVCI. Notable features include its compatibility with Rust for driver development and the ability to hook and modify any specified system service number (SSN), making it a versatile tool for advanced kernel manipulation techniques.