KelvinMsft / TechMyths
☆17Updated last year
Related projects ⓘ
Alternatives and complementary repositories for TechMyths
- Code Integrity Violation Spotter☆17Updated 5 months ago
- ☆15Updated last year
- ☆16Updated 2 years ago
- use ce driver, kernel library.☆13Updated last year
- Simple Demo of using Windows Hypervisor Platform☆27Updated 7 months ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Dump PDB Symbols including support for Bochs Debugging Format (with wine support)☆14Updated last year
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆18Updated last month
- Based on nt5src☆15Updated last year
- EDR PoC WIP LLC☆10Updated 9 months ago
- ☆12Updated last year
- Windows Minidump loader for Ghidra☆19Updated 2 years ago
- dk is a WinDbg extenion for dumping memory data in meaningful and organized ways, it is an enhancement of my previous tokenext project.☆22Updated last year
- Basic utilities for executing, reading and writing 64-bit data in a 32-bit WoW64 process☆15Updated 2 years ago
- Windows driver template, using C++20 & cmake & GithubActions☆19Updated 3 months ago
- Windbg extension that allows you analyze Control Flow Guard map☆36Updated 3 years ago
- An example of how to use Microsoft Windows Warbird technology☆25Updated last year
- Dynamic Taint Analysis versus Obfuscated Self-Checking☆16Updated 3 years ago
- Simple DLL and client app that work together to hook all the functions in WinHvPlatform.dll in order to provide logging and introspection…☆13Updated 2 years ago
- Reverse engineered API for Microsoft's Time Travel Debugger☆32Updated 7 months ago
- XOrCryptEx lightweight C Utility/Algorithm☆11Updated 2 years ago
- .lib file for linking against the NT CRT☆20Updated 2 years ago
- A benign application used to demonstrate an EDR detection. This version is procedural (i.e., not object-oriented).☆0Updated 2 years ago
- LLVM based devirtualization PoC’s.☆20Updated 2 years ago
- ☆27Updated 4 years ago
- A demonstration of hooking into the VMProtect-2 virtual machine☆17Updated last year
- Triton based symbolic emulator☆16Updated 2 years ago
- Lightweight WINAPI tracing with Pin☆26Updated 5 years ago
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆36Updated 2 years ago
- automates exploits using ROP chains, using ntdll-scraper☆16Updated 2 years ago