Kernel Pack
Kernel Pack
Kernel Pack is the game-over tool that uses DOG (Data Only Gadgets) to obtain ring-0 access without requiring a custom kernel driver. It enables you to design, build, deploy, and control kernel‑level rootkits through a full-featured graphical C2 interface, all while operating transparently under VBS, HVCI, and kCET.
Important: Access Subject to Verification
Due to the nature of our tools, access to the software will only be provided after successful completion of a customer screening process.
Single‑user, single machine. Each license is watermarked and tied to the email used at purchase; one license per person, one machine per license.
Renewals: Special pricing is available for customers with an active license. Please contact support@exploitpack.com

Driverless Kernel Exploitation with DOG
Kernel Pack leverages DOG (Data Only Gadgets) , a post-exploitation toolkit that operates without requiring the load of a custom kernel driver. Instead of relying on an unsigned driver that can trigger PatchGuard, HVCI, or other modern mitigations, DOG works with existing kernel read/write primitives through driver exploits, built-in and ready to deploy, allowing the user to:
- Locate and classify kernel gadgets at runtime using signed, existing kernel code
- Resolve structures and offsets dynamically no hardcoded offsets per Windows build
- Chain data-oriented gadgets arbitrary kernel-level operations using existing signed kernel code.
- Undetected by VBS/HVCI bypasses VBS, HVCI, and kCET protections by operating entirely through data manipulation rather than code execution or control-flow hijacking.
This driverless approach means Kernel Pack can achieve kernel-level access while running in fully protected endpoints, reducing detection surface and bypassing common kernel integrity protections.
Main features list:
- Callback discovery zeroing/modification
- Privilege escalation of target PID (token-swap)
- Protected Process Light modification
- Controlled VA/PA Arbitrary Read
- Controlled VA/PA Aribitrary Write
- Code Injection
- Unlink (hiding) of target PID via Data
- LSASS PatchWDigest
- LSASS Dump Raw pages from memory
- LSASS Minidump + PPL Zeroing
- Suspend of target PID, works for Protected Processed
Do you need a quote? Contact us
Key Features
-
Kernel Callback & System Activity
Provides a kernel‑level view into registered callbacks from other drivers, including object callbacks and activity hooks for process/thread creation, image loading, and registry operations. It surfaces this visibility through a single callback action that lets you query, remove, or restore specific callback types, giving operators a focused way to inspect and manage kernel activity signals from one place.
-
Event Tracing for Windows (ETW)
Kernel Pack includes an ETW control that allows operators to toggle the Event Tracing for Windows Threat Intelligence (ETW-TI) provider on or off. The functionality is exposed via the etwti kernel command (enable/disable), which dispatches the request to the agent and executes the change in kernel context. This enables direct control over ETW-TI telemetry generation from the console.
-
Process Tampering
Provides kernel-level controls to protect, elevate, hide, or restore specific process IDs, all achieved through DOG's data-only gadget chaining without a custom kernel driver. These operations leverage existing signed kernel code, eliminating PatchGuard collision risks. The feature pairs with a DLL/PPL agent builder that packages a standard DLL implant or a PPL-bypass variant with optional KnownDLL unhooking to harden or shield protected processes.
-
Persistence Capabilities
Kernel-assisted mechanisms designed to support durable agent continuity across reboots and system disruptions, particularly in environments where userland persistence is unreliable or heavily monitored. By operating at a lower system level, these capabilities offer improved resilience and reduced exposure to common detection methods compared to traditional autorun techniques
-
Privilege Elevation & PPL Process
Privilege Elevation & Process Signature Control (PP / PPL) exposes elevation and signature actions through the kernel‑level process controls and provides a dedicated DLL/PPL implant builder for protected‑process scenarios. Operators can select, elevate or change PPL for a target PID via the process command flow.
-
Callback modification and zeroing
Provides a focused kernel‑level control surface for inspecting and managing callback registrations including object callbacks and the process/thread creation, image load, and registry callback routines, while also offering a direct toggle for the ETW Threat Intelligence provider. These controls let operators query, remove, or restore callbacks and quickly enable or disable event visibility through a single, consistent command flow.
-
Credential Access Capabilities
Centralises sensitive post-execution actions by leveraging DOG's data-only gadget chains to perform credential extraction from LSASS memory without relying on a custom kernel driver. It provides two injection paths: DLL injection and Shellcode injection, each configurable by target PID, payload path, and delivery method (APC or remote thread), with injection operations also carried out through DOG's gadget chaining using existing signed kernel code.
-
Dumping Credentials from LSASS
Designed to support advanced post-exploitation workflows where credential material is required.
The agent performs a kernel-level operation that targets the LSASS process memory and extracts 3DES keys associated with protected authentication data. This capability is very useful during Red Team engagements and provides a structured method for retrieving credential-related artifacts from secured system components.
Kernel Pack Licensing FAQ
What type of license is included?
All our tools are provided under an annual license.
Do licenses renew automatically?
Licenses are not automatically renewed. You may choose to renew each year at your own convenience. Special pricing applies to renewals.
How many users can use one license?
Each license is issued on a single-user basis. Sharing between multiple individuals is not permitted.
Integration with other tools
Kernel Pack is the final stage in the stack: When authorized and required, it extends post-exploitation capabilities to the kernel level for advanced testing scenarios. The “ultimate” controlled evaluation phase for red teams.
Can I use the license against multiple targets?
Yes. While some tools in the industry restrict you to a limited number of targets, our licenses allow you to use the tool against as many machines as needed.
Delivery of licenses
Licenses are delivered digitally to the email used at purchase. Since they are sent manually, delivery may take up to 24 hours (usually faster).
Once the order is confirmed and the license has been delivered, it cannot be transferred, and refunds will not be issued.
You may also like..
-
Windows Kernel Exploitation [Fundamentals]
Regular price From €600 EURRegular priceEURSale price From €600 EUR -
Windows Kernel: Vulnerability Hunting Training
Regular price From €600 EURRegular priceEURSale price From €600 EUR -
Windows Kernel Exploitation [Advanced]
Regular price From €600 EURRegular priceEURSale price From €600 EUR