← Back to driver explorer
Driver intelligenceVulnerableVerified

ktapi.sys

ktapi.sys is a legacy cross-signed Kontron Technology Application Programming Interface driver that exposes the \\.\ktapi device to user mode. IOCTL 0x82007000 accepts a caller-controlled interface type, bus address, and size before using HalTranslateBusAddress, ZwOpenSection, and ZwMapViewOfSection to map physical memory into the calling process. Certain interface types cause HalTranslateBusAddress to return the supplied address unchanged, allowing an attacker to map arbitrary system RAM for physical-memory read and write. Expel documented this primitive in an EDR-killer exploit used by The Gentlemen ransomware group to obtain kernel code execution and terminate security processes.

UUID / 8a6aebaa-34aa-46e8-a864-4189a55fd17bADDED / 2026-07-10AUTHOR / Aaron Walton

Known samples 3

0 recorded TRUE · 0 recorded FALSE · 3 unknown for loading despite HVCI. Results apply to individual samples.

ktapi.sysSample 1 · HVCI unknown
MD5
96a8b9db2dc9cba8cdf90c7c33fe11c4
SHA1
86c85f4cbc36377d6fdb3f2af7d3049d5174c62c
SHA256
7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237
Imphash
70988f60e2fd3f3d7776089a737aece5
Authentihash MD5
7b6216d216bfa67fd891f220599768ee
Authentihash SHA1
fb2670420e6096cda9c873d7dc4199de3b2ea870
Authentihash SHA256
5936c769202e628091702af98691e8ee838bf0acbefba7731322457f254665de
Machine
AMD64
Version
1.0.1899 built by: WinDDK
Publisher
Kontron Technology A/S
ktapi.sysSample 2 · HVCI unknown
MD5
2c10be1aea72b7bdf07c735a4ad68876
SHA1
8b5cf43fba2c2226e6146ee065490dad17acc820
SHA256
9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046
Imphash
70988f60e2fd3f3d7776089a737aece5
Authentihash MD5
8f02305dfbeb3df6ee48156fde37ab2f
Authentihash SHA1
da72619db2843aa91e5ba8b3467386e194f93c18
Authentihash SHA256
646a91c588bd5f0f2e7649723297211efec1fcbe92f44f4b3b8858350beaa402
Machine
AMD64
Version
1.0.2118 built by: WinDDK
Publisher
Kontron Technology A/S
ktapi.sysSample 3 · HVCI unknown
MD5
e3c123a2ee4720001ed35d45fa1e57eb
SHA1
92f5c4fd5791db408fa801fd3d887870691af1f8
SHA256
89ba754861e11d9db4440b2b5db61fd5bee16752e4623c4271b8fdd0a666c677
Imphash
ec4687bc52f296b7dcdfa7967aecbc0c
Authentihash MD5
fe3896c6129dd0b564f5051dbc80fb79
Authentihash SHA1
cc7b39806e076b266aabff1a7ca1e8cb62ca19dc
Authentihash SHA256
11101d0bf398ae0631904fff00431e0f23c0b13ca47055cafd797b2b48a6d44e
Machine
I386
Version
1.0.2118 built by: WinDDK
Publisher
Kontron Technology A/S

Recorded command

sc.exe create ktapi binPath=C:\windows\temp\ktapi.sys type=kernel && sc.exe start ktapi

Map arbitrary physical memory from user mode for kernel read/write and defense impairment. · Privileges: kernel · OS: Windows 10, Windows 11

Research & references

Acknowledgement: Aaron Walton @AaronWalton