Has anyone here ever used WinDbg kernel debugger to modify the SSDT in order to restore the original entries from ntoskrnl.exe?
i was wondering if it would be possible to write a script or using its extensions for such operation??
i just want to be able to do this manually on a system using a debugger, if possible.






