Sentinel-One / SKREAM
SentinelOne's KeRnel Exploits Advanced Mitigations
☆52Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for SKREAM
- Windbg2ida lets you dump each step in Windbg then shows these steps in IDA☆73Updated 4 months ago
- A fast execution trace symbolizer for Windows.☆130Updated 6 months ago
- ☆33Updated 3 years ago
- POC viruses I have created to demo some ideas☆59Updated 4 years ago
- Python bindings for the Microsoft Hypervisor Platform APIs.☆66Updated 5 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆71Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 2 years ago
- Flare-On solutions☆36Updated 5 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆59Updated 8 years ago
- Import DynamoRIO drcov code coverage data into Ghidra☆42Updated 11 months ago
- windbg plugin for win32k debugging☆72Updated 5 years ago
- Resources for the workshop titled "Repacking the unpacker: Applying Time Travel Debugging to malware analysis", given at HackLu 2019☆39Updated 5 years ago
- kernel pool windbg extension☆79Updated 9 years ago
- VMX intrinsics plugin for Hex-Rays decompiler☆70Updated 5 years ago
- Elevation of privilege detector based on HyperPlatform☆117Updated 7 years ago
- Hyper-V Research is trendy now☆172Updated 6 months ago
- ☆47Updated 7 years ago
- ☆60Updated 5 years ago
- Tools made for my Hyper-V blog series @ https://foxhex0ne.blogspot.com/☆54Updated 4 years ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆117Updated 4 years ago
- Simple library to spray the Windows Kernel Pool☆104Updated 4 years ago
- ☆33Updated last year
- Static unpacker for FinSpy VM☆97Updated 3 years ago
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆66Updated 4 years ago
- ☆44Updated 4 years ago
- Hyper-V scripts☆112Updated last year
- clone of armadillo patched for windows☆46Updated 3 weeks ago
- Ebfuscator: Abusing system errors for binary obfuscation☆52Updated 4 years ago
- CVE-2020-0890 | Windows Hyper-V Denial of Service Vulnerability proof-of-concept code☆36Updated 4 years ago
- IDA plugin to explore and browse tags☆52Updated 5 years ago