VoidSec / DriverBuddyReloaded
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks
☆326Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for DriverBuddyReloaded
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆548Updated last month
- Debugger Anti-Detection Benchmark☆291Updated 11 months ago
- IDA Pro plugin to make bitfield accesses easier to grep☆229Updated 7 months ago
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆226Updated 3 months ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆267Updated last year
- Research on Windows Kernel Executive Callback Objects☆278Updated 4 years ago
- A library to develop kernel level Windows payloads for post HVCI era☆366Updated 3 years ago
- Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!☆259Updated 3 weeks ago
- A VMP to VTIL lifter.☆424Updated 3 years ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆261Updated last month
- System call hook for Windows 10 20H1☆481Updated 3 years ago
- Advanced driver monitoring utility.☆201Updated 2 years ago
- Analyze patches in a process☆247Updated 3 years ago
- SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.☆356Updated 3 years ago
- A x64 Windows Rootkit using SSDT or Hypervisor hook☆512Updated 3 weeks ago
- x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code☆196Updated 3 years ago
- Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.☆845Updated 5 years ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆205Updated 5 years ago
- Load your driver like win32k.sys☆246Updated 2 years ago
- Windows NT x64 syscall fuzzer☆589Updated last year
- HashDB API hash lookup plugin for IDA Pro☆296Updated last month
- Native code virtualizer for x64 binaries☆403Updated this week
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated 10 months ago
- Header only wrapper around Hex-Rays API in C++20.☆151Updated 2 years ago
- Shell extension for opening executables in IDA☆185Updated last year
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆196Updated 2 years ago
- ☆181Updated last year
- APC Internals Research Code☆158Updated 4 years ago
- This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially docum…☆161Updated 5 months ago