KDU, or Kernel Driver Utility, is a Windows research tool for exploring kernel components without requiring a full local debugging setup. It uses known vulnerable third-party drivers as providers for privileged kernel access. The utility can inspect protected processes, modify certain process protections, access process memory, and examine Driver Signature Enforcement state. It also contains research functionality for mapping specially designed drivers into kernel memory. Diagnostic commands and provider listings help users inspect compatibility across supported Windows versions. Because it deliberately interacts with sensitive kernel protections and vulnerable drivers, it is intended for controlled research environments and can cause system instability.
Features
- Windows kernel research utilities
- Vulnerable driver provider framework
- Protected process inspection
- Kernel and process memory access
- Driver Signature Enforcement research
- System diagnostics and provider reporting