SekoiaLab / BinaryInjectionMitigation
Two tools used during our analysis of the Microsoft binary injection mitigation implemented in Edge TH2.
☆53Updated 7 years ago
Alternatives and similar repositories for BinaryInjectionMitigation:
Users that are interested in BinaryInjectionMitigation are comparing it to the libraries listed below
- A windbg extension, extracting token related contents☆41Updated 4 years ago
- A dirty IDAPython script to dump windows system call number/name pairs as JSON☆37Updated 7 years ago
- A sample project for using Capstone from a driver in Visual Studio 2015☆33Updated 8 years ago
- kernel exploitation helper class☆76Updated 8 years ago
- PoC for Bypassing UM Hooks By Bruteforcing Intel Syscalls☆39Updated 9 years ago
- ☆28Updated 7 years ago
- ☆33Updated 9 years ago
- Anti-technique Codes, Detection of Anti-technique codes☆37Updated 11 years ago
- Windows SMEP Bypass U=S☆37Updated 8 years ago
- PCAUSA Rawether for Windows Local Privilege Escalation☆38Updated 7 years ago
- Windows kernel vulnerability in win32k.sys Driver☆34Updated 9 years ago
- A Fuzzer for Windows NDIS Drivers OID Handlers☆93Updated 3 years ago
- Old exploits and code for my self-referencing PML4 technique (2014)☆31Updated 9 years ago
- IDAScript to create Symbol file which can be loaded in WinDbg via AddSyntheticSymbol☆40Updated 10 years ago
- Slides of 44Con 2018☆21Updated 6 years ago
- ☆31Updated 7 years ago
- Import debugging traces from WinDBG into IDA. Color the graph, fill in the value of all the operands, etc.☆25Updated 12 years ago
- Anti-AV compilation☆42Updated 11 years ago
- ☆39Updated 3 years ago
- Internet Explorer Exploit with CFG bypass for Windows 10☆54Updated 8 years ago
- ☆50Updated 7 years ago
- Exploiting CVE-2016-0040 uninitialized pointer☆45Updated 8 years ago
- ☆34Updated 7 years ago
- Bootkits Revisited☆41Updated 10 years ago
- HackSys Extreme Vulnerable Driver - StackOverflow Exploit☆31Updated 8 years ago
- Supporting Files on my analysis of the malware designated hdroot.☆59Updated 7 years ago
- Implements the POP/MOV SS (CVE-2018-8897) vulnerability by leveraging SYSCALL to perform a local privilege escalation (LPE).☆116Updated 6 years ago
- ☆33Updated 7 years ago
- A static Internet Explorer Fuzzer.☆50Updated 7 years ago
- ☆45Updated 6 years ago