VergiliusProject / vergilius-project
This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially documented and cannot be found in Windows Driver Kit (WDK) headers. The target audience of this site is driver developers and kernel researches.
☆194Updated last month
Alternatives and similar repositories for vergilius-project:
Users that are interested in vergilius-project are comparing it to the libraries listed below
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆344Updated 4 months ago
- Research on Windows Kernel Executive Callback Objects☆285Updated 5 years ago
- APC Internals Research Code☆162Updated 4 years ago
- A library to develop kernel level Windows payloads for post HVCI era☆396Updated 3 years ago
- Debugger Anti-Detection Benchmark☆311Updated last year
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆209Updated 5 years ago
- Advanced driver monitoring utility.☆206Updated 2 years ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆203Updated 2 years ago
- IDA Pro plugin to make bitfield accesses easier to grep☆232Updated last month
- Code Injection, Inject malicious payload via pagetables pml4.☆232Updated 3 years ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆584Updated last month
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆244Updated 2 years ago
- MemoryRanger protects kernel data and code by running drivers and hosting data in isolated kernel enclaves using VT-x and EPT features. M…☆223Updated 4 years ago
- Bindings for Microsoft WinDBG TTD☆216Updated last year
- A more stealthy variant of "DLL hollowing"☆342Updated last year
- An IDA Plugin that help analyzing module that use COM☆204Updated last year
- Yet another windows internals repo☆205Updated 3 years ago
- Analyze patches in a process☆250Updated 3 years ago
- A modern c++ implementation of windows heavens gate☆216Updated 4 years ago
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆141Updated 2 years ago
- x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code☆203Updated 3 years ago
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆136Updated 2 years ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆225Updated 2 years ago
- Browse Page Tables on Windows (Page Table Viewer)☆196Updated 2 years ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆131Updated 6 months ago
- Asynchronous Procedure Calls☆219Updated 3 years ago
- This is a collection of interesting codes about Windows Process creation.☆232Updated last year
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- Set of antianalysis techniques found in malware☆129Updated last year
- Toy scripts for playing with WinDbg JS API☆225Updated 8 months ago