logo

Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows

ID: e1066dda-e5b8-58fb-94e5-8be224abc9e0

STIX ID: report--e1066dda-e5b8-58fb-94e5-8be224abc9e0

Feed Name: Connor McGarr’s Blog

Date Published: 2025-02-03

Date Updated: 2026-04-19

Author: Connor McGarr

...
...

This technical blog reverse-engineers Windows’ kernel-mode Intel CET (Shadow Stack) implementation, explaining how NT initializes kernel shadow stacks and how the Secure Kernel (under VBS/HVCI) finalizes and protects them using NARs, hypercalls (HvCallModifyVtlProtectionMask), and VMCS updates (VMX_GUEST_SSP). It covers stack creation for user threads’ kernel stacks, restore tokens and RSTORSSP usage, cached stack handling, and Secure Kernel assist routines for legitimate context restores—highlighting that kernel CET requires HVCI and relies on hypervisor-enforced protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.