Simple EFI runtime driver that hooks GetVariable function and returns data expected by Windows to make it think that it's running with secure boot enabled (faking secure boot)
☆237Oct 1, 2021Updated 4 years ago
Alternatives and similar repositories for SecureFakePkg
Users that are interested in SecureFakePkg are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Using Windows' own bootloader as a shim to bypass Secure Boot☆251Jul 17, 2024Updated 2 years ago
- Guide for patching AMI Aptio V UEFI firmware to circumvent Secure Boot checks☆139Jun 20, 2024Updated 2 years ago
- mouseclassservicecallback detection via hook☆53Feb 7, 2022Updated 4 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆201Jul 11, 2023Updated 3 years ago
- Just another .data pointer hook. This time it's hooking AfdIrpCallDispatch within Afd.sys☆11Feb 22, 2022Updated 4 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Discarded Section Manual Map☆69Jun 18, 2020Updated 6 years ago
- PoC EFI runtime driver for memory r/w & kdmapper fork☆585Nov 30, 2024Updated last year
- nmi stackwalking + module verification☆176Dec 28, 2023Updated 2 years ago
- Cheat for my own game SecureGame which uses a bootkit to hyperjack Hyper-V in order to access VBS enclave's memory☆136Dec 8, 2024Updated last year
- reverse engineering of the windows nt kernel debugger protocol & reimplementation.☆43Jul 2, 2024Updated 2 years ago
- manually map driver for a signed driver memory space☆179Mar 11, 2021Updated 5 years ago
- usermode driver mapper that forcefully loads any signed kernel driver (legit cert) with a big enough section (example: .data, .rdata) to …☆508Jan 3, 2022Updated 4 years ago
- Old way for blocking NMI interrupts☆29Sep 6, 2022Updated 4 years ago
- ☆141Jan 13, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Minimalistic AMD-V/SVM hypervisor with memory introspection capabilities☆435Feb 26, 2025Updated last year
- Simple proof of concept kernel mode driver hooking tpm.sys dispatch to randomize any public key reads☆248Dec 16, 2023Updated 2 years ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆117Feb 8, 2022Updated 4 years ago
- PoC HWID spoofer that runs in EFI☆364Dec 26, 2024Updated last year
- Hide SMBIOS/disk/NIC serials from EFI bootkit☆337May 14, 2021Updated 5 years ago
- Cool kernel communication method.☆95Jun 27, 2021Updated 5 years ago
- A mapper that maps shellcode into loaded large page drivers☆368Apr 26, 2022Updated 4 years ago
- A kernelmode driver swapping a .data pointer in the kernel to perform communication between the kernel and usermode.☆136Oct 20, 2020Updated 5 years ago
- hooks gServerHandlers xxxEventWndProc☆12May 1, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Load your driver like win32k.sys☆257Aug 20, 2022Updated 4 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆387Aug 18, 2022Updated 4 years ago
- Hooking Windows' exception dispatcher to protect process's PML4☆271Jan 24, 2025Updated last year
- Mapping your code on a 0x1000 size page☆70May 20, 2022Updated 4 years ago
- Bypassing EasyAntiCheat.sys self-integrity by abusing call hierarchy☆81Oct 6, 2022Updated 3 years ago
- alternative smm driver for ryzen motherboards☆202Oct 12, 2024Updated last year
- Code Injection, Inject malicious payload via pagetables pml4.☆244Jul 7, 2021Updated 5 years ago
- Disks for DMA☆161Apr 28, 2021Updated 5 years ago
- Easy Anti PatchGuard☆218Apr 9, 2021Updated 5 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Rendering on external windows via hijacking thread contexts☆405Jun 28, 2020Updated 6 years ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆319May 31, 2023Updated 3 years ago
- An example code of CiGetCertPublisherName☆15Mar 24, 2022Updated 4 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆267Aug 31, 2022Updated 4 years ago
- Hide external overlay by using SetWindowDisplayAffinity☆102Sep 5, 2021Updated 5 years ago
- ☆75Dec 17, 2020Updated 5 years ago
- ☆294Sep 2, 2025Updated last year