Cr4sh / efiXplorer
IDA plugin for UEFI firmware analysis and reverse engineering automation
☆10Updated 2 years ago
Alternatives and similar repositories for efiXplorer:
Users that are interested in efiXplorer are comparing it to the libraries listed below
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆10Updated 6 years ago
- SMM UEFI module and client for UMD privilege escalation☆30Updated last year
- ☆21Updated 3 years ago
- NT AUTHORITY\SYSTEM☆37Updated 4 years ago
- Take back control of Windows Code Integrity, no exploits or patching required! Requires that you control your own Platform Key (PK).☆41Updated 2 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆69Updated last year
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆13Updated last year
- UEFI bootkit: Hardware Implant. In-Progress☆12Updated 2 years ago
- ☆8Updated 6 months ago
- Example payload for CVE-2022-21894☆12Updated last year
- ☆10Updated 7 years ago
- 2022 Updated Kernelmode-Code☆31Updated 10 months ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆58Updated 5 months ago
- Exploits pack for the Windows Kernel mode driver HackSysExtremeVulnerableDriver written for educational purposes.☆65Updated 3 years ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- System Management RAM analysis tool☆74Updated 5 months ago
- Another UEFI runtime bootkit☆28Updated last year
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- A collection of tools, source code, and papers researching Windows' implementation of CET.☆79Updated 4 years ago
- Implementation of Advanced Module Stomping and Heap/Stack Encryption☆9Updated last year
- Plugins related to LeechCore☆34Updated last week
- An x64dbg plugin which marks XFG call signatures as data☆73Updated last year
- Exploit POC for CVE-2024-36877☆46Updated 5 months ago
- A packed & protected Module Loader and more, for 64-bit Windows☆28Updated 3 years ago
- Information about a signed UEFI Shell that can be used when Secure Boot is enabled.☆79Updated 3 years ago
- UPDATED 2022 Flame malware sourcecode available !! Forked. I will later provide my sample of Flame, Duqu and Gauss.☆19Updated 10 months ago
- Yet another Windows DLL injector.☆38Updated 3 years ago
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆27Updated 2 years ago
- Writeup and scripts for the 2021 malwarebytes crackme☆10Updated 3 years ago
- Neutralize KEPServerEX anti-debugging techniques☆31Updated last year