POPFD / cascade
A thin introspection hypervisor framework that allows for low level resource manipulation.
☆13Updated last year
Alternatives and similar repositories for cascade:
Users that are interested in cascade are comparing it to the libraries listed below
- A demonstration of hooking into the VMProtect-2 virtual machine☆17Updated last year
- This is a ring -1 header framework in order to simplify the creation of hypervisors on SVM☆22Updated last year
- EDR PoC WIP LLC☆10Updated last year
- Plugin for x64dbg to disable parallel loading of dependencies☆19Updated 2 years ago
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆33Updated last year
- AMD SVM hypervisor rootkit proof of concept☆44Updated last year
- How Meltdown and Spectre haunt Anti-Cheat: DVRT details☆21Updated 5 months ago
- ☆16Updated 2 years ago
- PDB Rewriting Rust Library☆23Updated 9 months ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- ASUSTeK AsIO3 I/O driver unlock☆20Updated 3 years ago
- ☆15Updated last year
- Unicorn Engine port for UEFI firmware☆46Updated 2 months ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- An example of how to use Microsoft Windows Warbird technology☆27Updated last year
- Elevate arbitrary MSR writes to kernel execution.☆26Updated last year
- Binary Ninja plugin to perform automated analysis of Windows drivers☆17Updated 5 years ago
- A basic Secure Virtual Machine hypervisor☆20Updated 3 years ago
- Native API header files for the Process Hacker project (nightly).☆25Updated this week
- Extensions for x64dbg written in Rust: Telescope and Unicorn powered disassembly☆24Updated last year
- Simple Intel VT-x type-2 hypervisor for 64-bit Linux.☆17Updated 4 years ago
- Symbolic Execution based on lifting amd64 to z3☆21Updated 7 months ago
- Experiment building lifting-bits dependencies with pure CMake. Migrated to:☆21Updated 4 months ago
- Runtime smm module loader☆32Updated 2 years ago
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆32Updated 4 months ago
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆18Updated 4 months ago
- Binary Ninja plugin for automating VMProtect analysis☆58Updated 2 years ago
- Rust library for lifting raw binary data to LLVM IR☆44Updated 4 months ago
- My research WIP bluepill hypervisor☆41Updated last year
- A driver to implement IOCTL hooking☆24Updated 2 years ago