Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows
ID: e1066dda-e5b8-58fb-94e5-8be224abc9e0
STIX ID: report--e1066dda-e5b8-58fb-94e5-8be224abc9e0
Feed Name: Connor McGarr’s Blog
This technical blog reverse-engineers Windows’ kernel-mode Intel CET (Shadow Stack) implementation, explaining how NT initializes kernel shadow stacks and how the Secure Kernel (under VBS/HVCI) finalizes and protects them using NARs, hypercalls (HvCallModifyVtlProtectionMask), and VMCS updates (VMX_GUEST_SSP). It covers stack creation for user threads’ kernel stacks, restore tokens and RSTORSSP usage, cached stack handling, and Secure Kernel assist routines for legitimate context restores—highlighting that kernel CET requires HVCI and relies on hypervisor-enforced protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
