LordNoteworthy / windows-exploitation
My notes while studying Windows exploitation
☆180Updated last year
Related projects: ⓘ
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆116Updated last year
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆114Updated last year
- Virus Exchange (VX) - Collection of malware or assembly code used for "offensive" purposed.☆176Updated 2 years ago
- Important notes and topics on my journey towards mastering Windows Internals☆330Updated 4 months ago
- Exploit Development - Weaponized Exploit and Proof of Concepts (PoC)☆213Updated last year
- Repository to publish your evasion techniques and contribute to the project☆128Updated 2 weeks ago
- Windows System Programming Experiments☆214Updated 2 years ago
- Recon 2023 slides and code☆77Updated last year
- Kernel Exploits☆240Updated 3 years ago
- A helper utility for creating shellcodes. Cleans MASM file generated by MSVC, gives refactoring hints.☆157Updated 2 months ago
- MalUnpack companion driver☆92Updated 3 months ago
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆334Updated this week
- ☆131Updated last year
- A curated list of awesome Windows Exploitation resources, and shiny things.☆68Updated 7 years ago
- Admin to Kernel code execution using the KSecDD driver☆232Updated 5 months ago
- Yet another variant of Process Hollowing☆349Updated 6 months ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆221Updated 2 years ago
- ☆92Updated this week
- A tutorial on how to write a packer for Windows!☆240Updated 9 months ago
- PoCs for Kernelmode rootkit techniques research.☆333Updated 2 weeks ago
- Side-by-side comparison of the Windows and Linux (GNU) Loaders☆269Updated 2 weeks ago
- Source code of exploiting windows API for red teaming series☆146Updated last year
- Set of antianalysis techniques found in malware☆124Updated last year
- Extract Windows Defender database from vdm files and unpack it☆419Updated 4 years ago
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆247Updated 8 months ago
- Advanced driver monitoring utility.☆194Updated 2 years ago
- A small x64 library to load dll's into memory.☆422Updated 10 months ago
- Do you want to use x64dbg instead of immunity debugger? oscp eCPPTv2 buffer overflow exploits pocs☆76Updated 8 months ago
- Tools and PoCs for Windows syscall investigation.☆349Updated 4 months ago
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆219Updated 11 months ago