0xcpu / ExecutiveCallbackObjects
Research on Windows Kernel Executive Callback Objects
☆278Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for ExecutiveCallbackObjects
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆206Updated 5 years ago
- A library to develop kernel level Windows payloads for post HVCI era☆366Updated 3 years ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆548Updated last month
- MemoryRanger protects kernel data and code by running drivers and hosting data in isolated kernel enclaves using VT-x and EPT features. M…☆219Updated 4 years ago
- Translates WinDbg "dt" structure dump to a C structure☆126Updated 8 years ago
- This is a collection of interesting codes about Windows Process creation.☆230Updated 10 months ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆327Updated 3 weeks ago
- APC Internals Research Code☆159Updated 4 years ago
- Yet another windows internals repo☆205Updated 3 years ago
- SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.☆356Updated 3 years ago
- ☆151Updated last month
- Hyper-V Research is trendy now☆172Updated 6 months ago
- IDA Pro plugin to make bitfield accesses easier to grep☆229Updated 7 months ago
- Hyper-V Research is trendy now☆151Updated last month
- ☆121Updated last month
- A Windows kernel dump C++ parser library with Python 3 bindings.☆193Updated 4 months ago
- Windows NT x64 syscall fuzzer☆590Updated last year
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆310Updated 7 months ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆135Updated 5 years ago
- VT-based PCI device monitor (SPI)☆150Updated 4 years ago
- Header only wrapper around Hex-Rays API in C++20.☆151Updated 2 years ago
- An IDA Plugin that help analyzing module that use COM☆198Updated last year
- PoC exploiting Aligned Chunk Confusion on Windows kernel Segment Heap☆195Updated 4 years ago
- Toy scripts for playing with WinDbg JS API☆220Updated 4 months ago
- PatchGuard Research☆292Updated 6 years ago
- This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially docum…☆161Updated 5 months ago
- A native hypervisor designed for the Windows operating system☆120Updated 3 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆581Updated 7 years ago
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆124Updated last year