Executes Read/Write process memory with `NtQueryCompositionSurfaceStatistics`
☆23Feb 10, 2024Updated 2 years ago
Alternatives and similar repositories for rwDriver
Users that are interested in rwDriver are comparing it to the libraries listed below
Sorting:
- cr3 shuffle driver☆80Mar 24, 2024Updated last year
- ☆18Jan 11, 2026Updated 2 months ago
- ☆11Oct 24, 2022Updated 3 years ago
- Experiment to use sections as User/Kernelmode comm vector☆22Apr 7, 2023Updated 2 years ago
- How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver☆26May 29, 2023Updated 2 years ago
- ☆17Jun 30, 2020Updated 5 years ago
- Kernel-based memory hacking framework communicating with a kernel driver via sockets.☆97May 25, 2021Updated 4 years ago
- R3劫持所有异常☆15Jan 4, 2021Updated 5 years ago
- ☆17Apr 21, 2022Updated 3 years ago
- ☆48Jul 7, 2024Updated last year
- Windows kernel driver that detects hypervisors by probing SIDT/LIDT edge cases, paging/TLB behaviors, privilege transitions, and timing e…☆37Mar 3, 2026Updated 2 weeks ago
- ☆41Feb 16, 2024Updated 2 years ago
- Load driver on boot before anti-cheats☆37Feb 2, 2024Updated 2 years ago
- A C++/Asm template for PIC/EXE/DLL malware☆24Aug 12, 2025Updated 7 months ago
- Circumvents HWID bans on the rhythm game osu☆12Aug 4, 2019Updated 6 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆21Jan 1, 2025Updated last year
- Static user/kernel mode library that allows access to all functions and global variables by extracting offsets from the PDB☆118May 29, 2025Updated 9 months ago
- A lightweight Windows Prefetch file parser to extract programs' execution history☆68Jan 12, 2026Updated 2 months ago
- WinHvShellcodeEmulator (WHSE) is a shellcode emulator leveraging the Windows Hypervisor Platform API☆26Apr 24, 2022Updated 3 years ago
- ☆20May 17, 2022Updated 3 years ago
- Kernel Level NMI Callback Blocker☆168Sep 27, 2025Updated 5 months ago
- ☆13Sep 21, 2025Updated 6 months ago
- kernel to user mode APC injector☆46Mar 19, 2022Updated 4 years ago
- A simple example how to decrypt kernel debugger data block☆32Feb 8, 2021Updated 5 years ago
- ☆68Sep 16, 2022Updated 3 years ago
- Win32 PE Anti-RE and Anti-debugging Framework☆13May 14, 2019Updated 6 years ago
- From C, Rust or Zig to binary shellcode compiler based on Mingw gcc. It allows using Win32 APIs and standard libraries without any change…☆53Updated this week
- A POC for Windows Extension Host hooking☆24Jul 13, 2019Updated 6 years ago
- simple zero-dependency timer implementation☆12May 24, 2023Updated 2 years ago
- Hijacking Hyper-V at Runtime with DDMA☆90Aug 13, 2025Updated 7 months ago
- ☆19Apr 9, 2024Updated last year
- This is a repo of my previous BEKernelDriver but updated to add better protections and a more detailed setup. also with a good bit of cod…☆140Sep 27, 2025Updated 5 months ago
- manual map unsigned driver over signed memory☆222Apr 11, 2024Updated last year
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆23Nov 22, 2021Updated 4 years ago
- DRM Library for Windows (x64) in C++☆29Oct 15, 2025Updated 5 months ago
- Interprocess communication via a covert timing channel☆26Oct 24, 2025Updated 4 months ago
- Vectored Exception Handling Hooking Class☆167Jan 14, 2019Updated 7 years ago
- PoC for Acronis Arbitrary File Read - CVE-2022-45451☆18Dec 20, 2022Updated 3 years ago
- i stole this from some guys private repo on github☆58Jul 11, 2021Updated 4 years ago