My repository to upload drivers from different books and all the information related to windows internals.
☆168Aug 16, 2019Updated 6 years ago
Alternatives and similar repositories for Windows-Internals
Users that are interested in Windows-Internals are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Solution for Ricardo Narvaja's C++ Exploiting Exercise☆12Jul 21, 2019Updated 7 years ago
- Research on Windows Kernel Executive Callback Objects☆317Feb 22, 2020Updated 6 years ago
- Process reimaging proof of concept code☆96Jun 21, 2019Updated 7 years ago
- Kernel Detective☆154May 24, 2026Updated last month
- Some crazy PE executables protection kernel driver☆20May 2, 2020Updated 6 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- windbg plugin for win32k debugging☆74Oct 14, 2019Updated 6 years ago
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆32Mar 22, 2017Updated 9 years ago
- Shellcode injection using debugging APIs☆19Jan 13, 2014Updated 12 years ago
- The Windows Kernel Programming book samples☆685Sep 25, 2023Updated 2 years ago
- My notes about Genyatyk VM crackme☆27Jun 27, 2020Updated 6 years ago
- Dump of win32k POCs for bugs I've found☆379Mar 6, 2022Updated 4 years ago
- PoC exploiting Aligned Chunk Confusion on Windows kernel Segment Heap☆211Jul 2, 2020Updated 6 years ago
- This is a collection of interesting codes about Windows Process creation.☆239Jan 12, 2024Updated 2 years ago
- 🧶 The Win32 usermode threading library with UMS/fibers/threads support☆30Jul 1, 2019Updated 7 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Hide codes/data in the kernel address space.☆185May 8, 2021Updated 5 years ago
- Tools made for my Hyper-V blog series @ https://foxhex0ne.blogspot.com/☆57Jun 21, 2020Updated 6 years ago
- C++ Exceptions in Windows Drivers☆220Dec 21, 2020Updated 5 years ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆244Nov 6, 2019Updated 6 years ago
- VT-based PCI device monitor (SPI)☆158Oct 29, 2020Updated 5 years ago
- exploit termdd.sys(support kb4499175)☆61Jul 15, 2019Updated 7 years ago
- win10 pgContext dynamic dump (btc version)☆115Jan 15, 2020Updated 6 years ago
- Confirms the capability of Hardware-Accelerated Virtualization Technology.☆10Feb 26, 2026Updated 4 months ago
- Open Course for diving security internal☆52Nov 11, 2019Updated 6 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Examples of leaking Kernel Mode information from User Mode on Windows☆645Jul 7, 2017Updated 9 years ago
- Simple library to handle PE files loading, relocating, get/set data, ..., in addition to process handling☆33Aug 7, 2019Updated 6 years ago
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆748Nov 1, 2024Updated last year
- Retrieve pointers to undocumented kernel functions and offsets to members within undocumented structures to use in your driver by using t…☆63Jun 19, 2019Updated 7 years ago
- c++ implementation of windows heavens gate☆70Feb 12, 2021Updated 5 years ago
- Exploiting HEVD's WriteWhatWhereIoctlDispatch for LPE on Windows 10 TH2 through RS3 using GDI objects.☆24Jan 23, 2018Updated 8 years ago
- Kernel Pool Monitor☆128Mar 6, 2022Updated 4 years ago
- r0akmap is a PoC driver manual mapper based on r0ak☆37Aug 18, 2018Updated 7 years ago
- My notes while studying Windows internals☆489Jul 6, 2026Updated 2 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- WinDBG Anti-RootKit Extension☆643Jul 29, 2020Updated 5 years ago
- A driver that hooks C: volume using symbolic link callback to track all FS access to the volume☆108Apr 24, 2020Updated 6 years ago
- An attempt to restore and adapt to modern Win10 version the 'Rootkit Arsenal' original code samples☆74Apr 11, 2022Updated 4 years ago
- Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.☆911Nov 21, 2019Updated 6 years ago
- Windows kernel hacking framework, driver template, hypervisor and API written on C++☆1,817Nov 12, 2023Updated 2 years ago
- Various shellcodes☆12Sep 1, 2020Updated 5 years ago
- Windows Object Explorer 64-bit☆1,952Jul 14, 2026Updated last week