UEFI Bootkit Framework that attacks boot-time Code Integrity
☆139Mar 15, 2026Updated 2 months ago
Alternatives and similar repositories for Elysium
Users that are interested in Elysium are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Leveraging TPM2 TCG Logs (Measured Boot) to Detect UEFI Drivers and Pre-Boot Applications☆21Mar 28, 2025Updated last year
- Abusing DDMA alongside Copy On Write for Cross Process Code Execution for a 3000$ Bug Bounty☆99Feb 1, 2026Updated 3 months ago
- A serie of exploits targeting eneio64.sys - Turning Physical Memory R/W into Virtual Memory R/W☆124Oct 19, 2025Updated 7 months ago
- Decrypting and intercepting encrypted imports of Vanguards Kernel Driver☆35Feb 13, 2024Updated 2 years ago
- Provides commands to read from and write to arbitrary kernel-mode memory for users with the Administrator privilege. HVCI compatible. No …☆24Jun 16, 2024Updated last year
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Simple single file header for creating zero imports drivers. Can be useful for bypassing forensic memory analysis performed by anticheats…☆23Updated this week
- SPI flash read MitM attack PoC☆41May 24, 2022Updated 4 years ago
- Simple anti-instrumentation with EFLAGS.AC☆17Mar 31, 2025Updated last year
- UEFI Bootkit with user-mode communication☆124Jun 14, 2025Updated 11 months ago
- uefi diskless persistence technique + OVMF secureboot bypass☆103Apr 22, 2024Updated 2 years ago
- Old project (2020) reformed. Modifies gRT->GetVariable sub function from EFI_APPLICATION. Tested on Win10 22H2 (AMD).☆57Feb 28, 2024Updated 2 years ago
- Detect suspend you process☆15Jun 7, 2023Updated 2 years ago
- DMA firmware☆11Nov 14, 2024Updated last year
- hijacks the discord overlay and draws imgui inside of it while remaining flagless due to the discord overlay devs being retarded☆24Apr 29, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ASM Bootkit that patches DSE at boot allowing to load unsigned drivers☆19Aug 24, 2025Updated 9 months ago
- The sequel to Voyager☆105Aug 21, 2024Updated last year
- An advanced DKOM for drivers with "DRIVER_OBJECT"☆23Feb 19, 2023Updated 3 years ago
- A demonstration of hooking into the VMProtect-2 virtual machine☆24Nov 9, 2023Updated 2 years ago
- Windows x64 DLL/Driver manual map injection on a non-present PML4E using physical memory read/writes, direct page table manipulation and …☆99Sep 28, 2025Updated 7 months ago
- A rust proof of concept to demonstrate registry overwriting via RegRestoreKey using the Offline Registry Library☆24Nov 13, 2025Updated 6 months ago
- ☆24Jul 24, 2023Updated 2 years ago
- Using the peculiar behaviour of the VPGATHER instructions to determine if an address will fault before it is truly accessed. All done in …☆56Dec 30, 2025Updated 4 months ago
- Simple and lightweight hypervisor for AMD processors☆44Oct 25, 2025Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- kASLR bypass technique on Intel CPUs.☆34May 18, 2025Updated last year
- Use XIGNCODE3 driver to cheat☆75May 1, 2026Updated 3 weeks ago
- just proof of concept. hooking MmCopyMemory PG safe.☆86Nov 13, 2023Updated 2 years ago
- Using ioctl major function swaps to "spoof" the ARP table☆15Sep 11, 2024Updated last year
- KVC enables unsigned driver loading via DSE bypass (g_CiOptions patch, skci.dll hijack, SeCiCallbacks redirection) and PP/PPL manipulatio…☆248Updated this week
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆51Jun 7, 2023Updated 2 years ago
- memory introspection and reverse engineering hypervisor powered by leveraging Hyper-V☆653Apr 13, 2026Updated last month
- Hooking Windows' exception dispatcher to protect process's PML4☆250Jan 24, 2025Updated last year
- IoCreateDriver Implementation, it can be useful if you're trying to bypass anticheats☆139Dec 4, 2025Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A custom tool to unpack VMProtect-obfuscated executables and restore the original binary☆49Jul 30, 2025Updated 9 months ago
- ApplyCalleeType IDA Plugin 🤙 — Reborn. Single-file port to IDA Pro 9.3 with right-click menu, live prototype editor, and full SAL/MSDN p…☆71Mar 9, 2026Updated 2 months ago
- page table manipulation to gain physical r/w☆44May 7, 2024Updated 2 years ago
- ☆19May 22, 2024Updated 2 years ago
- PoC over some VMP features☆27Jul 26, 2025Updated 10 months ago
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆275Mar 16, 2026Updated 2 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆83Dec 21, 2022Updated 3 years ago