PatchGuard-Win11
This repository contains some information for PatchGuard for Windows 11 (build 22000.xxx), to potentially help researchers, security professionals, and enthusiasts looking into PatchGuard for Windows 11.
KiFilterFiberContext/PatchGuardTVCallback.h
This header file contains the decompiled notification callback function (a PatchGuard check routine) found at the entry of 'KiFilterFiberContext' if 'PsIntegrityCheckEnabled' is greater than zero. It is similar to the historical and well-known huge 'FsRtlMdlReadCompleteDevEx'.
'ExCreateCallback' opens an existing callback object 'TV' which is registered at boot-time by an external binary.
PspProcessDelete.h
This header file contains the decompiled function 'PspProcessDelete', You are probably wondering why it has anything to do with PatchGuard, technically it does not but it serves a purpose for integrity checking. This function is usually used for termination of threads and it's processes' but other than that, there appears to be an integrity check for KeServiceDescriptorTable and KeServiceDescriptorTableShadow inside it which is independent on PatchGuard contexts or dedicated threads, as shown in the image below. 'qword_140C4ECB0' the checksum occurs depending on the random value generated with KiQueryUnbiaisedInterruptTime. And finally the DPC is inserted using KeInsertQueueDpc triggering a BugCheck.
Disclaimer
For educational and authorized security research only. Don't use on systems you don't own or have explicit permission to test. I'm not responsible for misuse. Use at your own risk.