ElliotKillick / operating-system-design-reviewView external linksLinks
Operating System Design Review: A systematic analysis of modern systems architecture
☆338Jan 11, 2026Updated last month
Alternatives and similar repositories for operating-system-design-review
Users that are interested in operating-system-design-review are comparing it to the libraries listed below
Sorting:
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆280Sep 18, 2024Updated last year
- Hardcore Debugging☆929Jan 6, 2026Updated last month
- For when DLLMain is the only way☆423Oct 29, 2024Updated last year
- Reverse engineering winapi function loadlibrary.☆232Apr 17, 2023Updated 2 years ago
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆100Jan 3, 2026Updated last month
- Perfect DLL Proxying using forwards with absolute paths.☆338Nov 3, 2025Updated 3 months ago
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆321Jan 17, 2024Updated 2 years ago
- Local & remote Windows DLL Proxying☆170Jun 17, 2024Updated last year
- Abusing Windows fork API and OneDrive.exe process to inject the malicious shellcode without allocating new RWX memory region.☆288May 27, 2024Updated last year
- Experimental Windows x64 Kernel Rootkit with anti-rootkit evasion features.☆587Aug 2, 2025Updated 6 months ago
- PoCs for Kernelmode rootkit techniques research.☆429Nov 4, 2025Updated 3 months ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆88Feb 11, 2024Updated 2 years ago
- Evasion by machine code de-optimization.☆416Jul 22, 2024Updated last year
- Sleep obfuscation☆265Dec 13, 2024Updated last year
- ☆147Oct 29, 2024Updated last year
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆243Sep 26, 2023Updated 2 years ago
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆408Jan 11, 2026Updated last month
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆194Nov 27, 2024Updated last year
- Reflective DLL Injection Made Bella☆248Jan 6, 2025Updated last year
- Tools for analyzing EDR agents☆277Jun 10, 2024Updated last year
- ☆333Sep 21, 2025Updated 4 months ago
- Generic PE loader for fast prototyping evasion techniques☆244Jul 2, 2024Updated last year
- Inject DLLs into the explorer process using icons☆403May 18, 2025Updated 8 months ago
- Anti-Rootkit/Anti-Cheat Driver to uncover unbacked or hidden kernel code.☆294Dec 10, 2025Updated 2 months ago
- The Definitive Guide To Process Cloning on Windows☆539Jan 3, 2024Updated 2 years ago
- Nameless C2 - A C2 with all its components written in Rust☆282Sep 26, 2024Updated last year
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆107Apr 18, 2024Updated last year
- Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process☆286Jan 21, 2024Updated 2 years ago
- ☆106Aug 21, 2024Updated last year
- ☆60Jan 9, 2023Updated 3 years ago
- PE (and elf now!) bin2bin obfuscator☆810Oct 11, 2025Updated 4 months ago
- ☆180Apr 24, 2025Updated 9 months ago
- A set of fully-undetectable process injection techniques abusing Windows Thread Pools☆1,243Dec 11, 2023Updated 2 years ago
- A BOF that runs unmanaged PEs inline☆678Oct 23, 2024Updated last year
- early cascade injection PoC based on Outflanks blog post, in rust☆62Nov 8, 2024Updated last year
- HookChain: A new perspective for Bypassing EDR Solutions☆585Jan 5, 2025Updated last year
- Tools and PoCs for Windows syscall investigation.☆368Dec 2, 2025Updated 2 months ago
- Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths☆358Aug 11, 2024Updated last year
- Admin to Kernel code execution using the KSecDD driver☆264Apr 19, 2024Updated last year