WinHvShellcodeEmulator (WHSE) is a shellcode emulator leveraging the Windows Hypervisor Platform API
☆26Apr 24, 2022Updated 3 years ago
Alternatives and similar repositories for whse
Users that are interested in whse are comparing it to the libraries listed below
Sorting:
- ☆12Jun 30, 2019Updated 6 years ago
- A project on the Unicorn emulator to emulate the code of Pe files in windows☆28Sep 12, 2024Updated last year
- Try to transport the tcpip stack of ReactOS to Windows XP.☆17Feb 27, 2014Updated 12 years ago
- ☆24Jul 15, 2023Updated 2 years ago
- Executes Read/Write process memory with `NtQueryCompositionSurfaceStatistics`☆23Feb 10, 2024Updated 2 years ago
- ☆49Feb 21, 2022Updated 4 years ago
- ☆20May 17, 2022Updated 3 years ago
- ☆23May 8, 2023Updated 2 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆53Apr 7, 2022Updated 3 years ago
- ☆23Jul 24, 2023Updated 2 years ago
- Experiment to use sections as User/Kernelmode comm vector☆22Apr 7, 2023Updated 2 years ago
- defender_database☆24Oct 31, 2023Updated 2 years ago
- A Windows Memory driver for game hacking purposes. Supports manual mapping with BlackBone and PastDSE.☆43Apr 23, 2021Updated 4 years ago
- Interprocess communication via a covert timing channel☆26Oct 24, 2025Updated 4 months ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆50Mar 22, 2023Updated 2 years ago
- ☆25May 21, 2021Updated 4 years ago
- ☆29Nov 22, 2023Updated 2 years ago
- ☆19Apr 14, 2023Updated 2 years ago
- DRM Library for Windows (x64) in C++☆29Oct 15, 2025Updated 4 months ago
- Tools that run inside the guest☆11Jan 2, 2020Updated 6 years ago
- simple zero-dependency timer implementation☆12May 24, 2023Updated 2 years ago
- type 1 thin hypervisor written in C++☆17Dec 18, 2024Updated last year
- A simple C++ driver base with KD data block☆11Jun 25, 2022Updated 3 years ago
- Simple C program to quickly deobfuscate windows executables protected with Arxan.☆14Dec 18, 2022Updated 3 years ago
- YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js☆11May 27, 2024Updated last year
- ☆17Jun 30, 2020Updated 5 years ago
- ☆69Aug 31, 2021Updated 4 years ago
- ☆68Dec 17, 2020Updated 5 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆32Dec 31, 2024Updated last year
- A Simple Example☆23Nov 30, 2018Updated 7 years ago
- Admin to Kernel code execution using the KSecDD driver☆265Apr 19, 2024Updated last year
- Simple IOCTL hooking driver for Kernel- User - Mode communication.☆11Jul 26, 2020Updated 5 years ago
- Definitely not for fuzzing☆11Oct 22, 2020Updated 5 years ago
- Win32 PE Anti-RE and Anti-debugging Framework☆13May 14, 2019Updated 6 years ago
- NVMe-oF for Windows.☆14Feb 4, 2023Updated 3 years ago
- ☆18Feb 6, 2019Updated 7 years ago
- PoC for Acronis Arbitrary File Read - CVE-2022-45451☆18Dec 20, 2022Updated 3 years ago
- pdb's function and global vars to offset☆10Apr 11, 2023Updated 2 years ago
- Enum and Remove Hook in Windows☆51Dec 11, 2025Updated 2 months ago