Adversaries may abuse the KernelCallbackTable of a process to hijack its execution flow in order to run their own payloads.

Tactics
TA0003 TA0004 TA0005

Sub-technique of
T1574


See: MITRE ATT&CK