Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
KProcTerminator — Windows kernel driver designed for terminating specific processes on a system | Kitploit
Tools/GitHubGitHub/gmh5225/kprocterminator
Defensive ToolsPrivilege EscalationPersistence MechanismsMalware AnalysisRed TeamingAnti-Bot
GitHubgmh5225/kprocterminator

KProcTerminator

Windows kernel driver designed for terminating specific processes on a system

View Repository
2 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Twitter

KProcTerminator

Overview

This repository, 'KProcTerminator', contains a Windows kernel driver designed for terminating specific processes on a system. It is meant to be loaded using kdmapper, a known tool for loading unsigned drivers into the Windows kernel space without a signed driver.

KProcTerminator Diagram

Warning

⚠️ This driver can terminate system processes, potentially leading to system instability or crashes.

Features

  • Terminates specified processes by name.
  • Continuously monitors and terminates target processes.
  • Leverages native Windows Kernel APIs for process management.

Prerequisites

  • 64-bit Windows environment.
  • Administrative privileges on the system.
  • Knowledge of Windows kernel mode operations.
  • kdmapper or similar tools for loading unsigned kernel drivers.

Compilation

Compile the driver using Microsoft Visual Studio with Windows Driver Kit (WDK).

Usage

  1. Driver Loading: Load the driver into the kernel using kdmapper or a similar tool, with administrative privileges.
  2. Operation: Post-loading, it will monitor and terminate the following processes:
    • EPProtectedService.exe
    • EPIntegrationService.exe
    • EPSecurityService.exe
  3. Monitoring: The driver operates silently. Check system logs for its activities.
  4. Unloading: The driver does not support unloading; reboot the system to remove it from operation.

Customization

Modify the driver to target different processes by altering the DriverEntry function. Re-compile post-modifications.

Download Tool