Pdawg-bytes / UEFIBootKit
A simple UEFI bootkit made by @NSG650 and me.
☆26Updated 4 months ago
Alternatives and similar repositories for UEFIBootKit
Users that are interested in UEFIBootKit are comparing it to the libraries listed below
Sorting:
- CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)☆44Updated 7 months ago
- A few examples of how to trap virtual memory access on Windows.☆30Updated 4 months ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- Report and exploit of CVE-2024-21305.☆34Updated last year
- Example payload for CVE-2022-21894☆13Updated last year
- ☆46Updated last month
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆27Updated 9 months ago
- A fully compatible replacement of Windows NT NtCreateLowBoxToken syscall - precisely restored from reverse engineering☆36Updated 4 months ago
- Proof-of-Concept for CVE-2024-26218☆51Updated last year
- Mentally ill EtwTi parser☆36Updated last month
- ☆25Updated 6 months ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆26Updated last year
- BINARLY Research Tools and PoCs☆36Updated 7 months ago
- ☆38Updated 2 months ago
- Repo with different exploits & PoCs☆64Updated this week
- Michelangelo REanimator bootkit and REcon 2023 talk slides/materials☆29Updated last year
- Plugin interface for remote communications with Binary Ninja database and MCP server for interfacing with LLMs.☆32Updated last week
- ☆30Updated 2 months ago
- ☆20Updated 4 months ago
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆34Updated last year
- PoC exploit for HP Hardware Diagnostic's EtdSupp driver☆50Updated 2 years ago
- ☆30Updated last month
- Custom instruction length for hex-rays☆18Updated 4 months ago
- ☆19Updated 2 months ago
- ☆30Updated last year
- Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver☆50Updated last year
- A fast method to intercept syscalls from any user-mode process using InstrumentationCallback and detect any process using Instrumentation…☆30Updated last year
- Windows AppLocker Driver (appid.sys) LPE☆56Updated 9 months ago
- ☆12Updated last year
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆76Updated 2 weeks ago