Another weird thing? The cr4.CET bit was set to TRUE in the early critical corruption bsods, in SYSTEM thread. At that time Alex had no Core Isolation enabled. As I get it, on Windows OS (10,11) kernel CET is enabled only when the prerequisite, Core Isolation (memory integrity, HVCI) was enabled[1,2].
I read in all documentation that the bit must only be set on processes/threads that use it.
[1] https://learn.microsoft.com/en-us/windows-server/security/kernel-mode-hardware-stack-protection
[2] Youtube: "No Hat 2024 - Andrea Allievi - [Keynote] Modern Mitigations in Windows OS: Enhancing Security AGAINST KERNEL EXPLOITATIONS"
(Andrea Allievi being the Microsoft main developer of the Core Isolation so you can certainly rely on the information.)
As Gary, even though I have dozens of laptops and PCs, no one is capable of Intel CET. In other words, I can't go looking (with KD). Who sets the bit then? Certainly not the secure kernel, because the critical corruption bsods were before Alex activated the Core Isolation and therefore, there was no secure kernel (no VTL 1).
Why is that so? That does not seem to be right to me. Who sets it then? Because it's set. As everybody can see. :D