LuckyPi / PushPin
☆82Updated 4 years ago
Alternatives and similar repositories for PushPin:
Users that are interested in PushPin are comparing it to the libraries listed below
- ☆153Updated 5 years ago
- Bypassing PatchGuard on modern x64 systems☆252Updated last year
- Autonomous pre-boot DMA attack hardware implant for M.2 slot based on PicoEVB development board☆73Updated last year
- codes for my blog post: https://secrary.com/Random/InstrumentationCallback/☆172Updated 7 years ago
- Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303☆108Updated 6 years ago
- x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code☆201Updated 3 years ago
- Kernel shellcode injector☆143Updated 3 years ago
- Load your driver like win32k.sys☆252Updated 2 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆243Updated 2 years ago
- Code Injection, Inject malicious payload via pagetables pml4.☆228Updated 3 years ago
- A collection of various vulnerable (mostly physical memory exposing) drivers.☆347Updated 2 years ago
- Browse Page Tables on Windows (Page Table Viewer)☆193Updated 2 years ago
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆139Updated 3 years ago
- Resolve DOS MZ executable symbols at runtime☆96Updated 3 years ago
- A mapper that maps shellcode into loaded large page drivers☆252Updated 2 years ago
- Exploit MsIo vulnerable driver☆92Updated 3 years ago
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆265Updated 2 years ago
- Hide codes/data in the kernel address space.☆188Updated 3 years ago
- Plugins related to LeechCore☆34Updated last month
- An example of how x64 kernel shellcode can dynamically find and use APIs☆104Updated 4 years ago
- This tiny project prevents the signtool from verifing cert time validity and let you sign your bin with outdated cert without changing sy…☆228Updated 6 years ago
- Kernel driver loader using vulnerable gigabyte driver (https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vu…☆233Updated 3 years ago
- Kernel LdrLoadDll injector☆258Updated 6 years ago
- A novel technique to communicate between threads using the standard ETHREAD structure☆110Updated 3 years ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆113Updated last year
- Elevate a process to be a protected process☆144Updated 5 years ago
- Run Processes as PPL with ELAM☆153Updated 2 years ago
- DSE bypass using a leaked cert and adjusting the current clock.☆145Updated 2 years ago
- A library to read physical memory and system-wide virtual memory.☆125Updated 6 years ago
- TS-Changer - Forces the machine in/out of TestSigning Mode at runtime.☆65Updated last year