physical memory scanning tool scans kernel physical memory and iterates through PTEs What you can achieve by messing with physical memory: internal bypass HWID spoofing detecting Manual mapped drivers & DLLs