First off: this is the first time I "seriously" reversed a kernel-mode NT driver, so keep that in mind when you read this..
The Komodia rootkit config is located in a certain registry entry that's hardcoded in the driver. For Qustodio, it's
The config structure is simple enough. An array of the following structure:
DWORD type; BYTE unknown; // I don't see anywhere that the driver actually *reads* any of this part, // at least, not after writing to it first.