A little project I made while learning windows kernel programming.
A tiny EDR for Dummies. Uses Kernel Callbacks to detect process creation, thread creation, registry modification and loading of image files like EXE,DLL & SYS
Windows Kernel Programming (book) - @zodiacon amazon