Truneski / WindowsKernelProgramming-Exercises
☆49Updated 5 years ago
Alternatives and similar repositories for WindowsKernelProgramming-Exercises:
Users that are interested in WindowsKernelProgramming-Exercises are comparing it to the libraries listed below
- Process reimaging proof of concept code☆96Updated 5 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- Sysmon shenanigans☆65Updated 4 years ago
- Analyze and attack windows applications using dll hijacking vulnerabilities☆56Updated 5 years ago
- A simple tool to view important DLL Characteristics and change DEP and ASLR☆44Updated 6 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 7 years ago
- Blog posts☆30Updated 4 years ago
- ☆31Updated 4 years ago
- ☆45Updated 6 years ago
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆43Updated 3 years ago
- Malware Analysis, Anti-Analysis, and Anti-Anti-Analysis☆45Updated 7 years ago
- The Minimalistic x86/x64 API Hooking Library for Windows☆32Updated 7 years ago
- ☆22Updated 4 years ago
- Master list of all my vulnerability discoveries. Mostly 3rd party kernel drivers.☆49Updated 4 years ago
- A small library helping to parse commandline parameters (for C/C++)☆57Updated last year
- Public documents related to my talk "Bypass Windows Exploit Guard ASR" at Offensive Con 2019.☆93Updated 6 years ago
- Command like tool to print mitigation flags for running processes in a memory dump☆46Updated 4 years ago
- Local OXID Resolver (LCLOR) : Research and Tooling☆35Updated 3 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆77Updated 9 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆55Updated 2 years ago
- Designed to learn OS specific anti-emulation patterns by fuzzing the Windows API.☆98Updated 4 years ago
- Example for PagedOut!☆24Updated 5 years ago
- A windbg extension for ASLR/DEP/SafeSEH check☆25Updated 6 years ago
- ☆36Updated 5 years ago
- PoC for Bypassing UM Hooks By Bruteforcing Intel Syscalls☆38Updated 9 years ago
- exploit termdd.sys(support kb4499175)☆59Updated 5 years ago
- An command-line RPC method enumerator, born out of RPCView's awesomeness☆104Updated 5 years ago
- An example of how x64 kernel shellcode can dynamically find and use APIs☆105Updated 4 years ago
- ☆51Updated 8 years ago
- Resources for the workshop titled "Repacking the unpacker: Applying Time Travel Debugging to malware analysis", given at HackLu 2019☆41Updated 5 years ago