ayoubfaouzi / windows-exploitation
My notes while studying Windows exploitation
☆184Updated last year
Related projects ⓘ
Alternatives and complementary repositories for windows-exploitation
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆115Updated last year
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆123Updated 2 years ago
- Important notes and topics on my journey towards mastering Windows Internals☆341Updated 6 months ago
- Kernel Exploits☆242Updated 3 years ago
- A curated list of awesome Windows Exploitation resources, and shiny things.☆69Updated 7 years ago
- Recon 2023 slides and code☆79Updated last year
- My notes while studying Windows internals☆400Updated this week
- Virus Exchange (VX) - Collection of malware or assembly code used for "offensive" purposed.☆178Updated 2 years ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆221Updated 2 years ago
- Exploit Development - Weaponized Exploit and Proof of Concepts (PoC)☆216Updated last year
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆139Updated this week
- Admin to Kernel code execution using the KSecDD driver☆238Updated 7 months ago
- A tutorial on how to write a packer for Windows!☆248Updated 11 months ago
- MalUnpack companion driver☆92Updated 5 months ago
- A small x64 library to load dll's into memory.☆424Updated last year
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆343Updated 3 weeks ago
- Advanced driver monitoring utility.☆201Updated 2 years ago
- Set of antianalysis techniques found in malware☆129Updated last year
- Tools and PoCs for Windows syscall investigation.☆353Updated 6 months ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated 10 months ago
- Do you want to use x64dbg instead of immunity debugger? oscp eCPPTv2 buffer overflow exploits pocs☆78Updated 10 months ago
- Vulnerable driver research tool, result and exploit PoCs☆181Updated last year
- ☆135Updated 3 years ago
- ☆131Updated last year
- Yet another windows internals repo☆205Updated 3 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆111Updated 4 months ago
- Windows System Programming Experiments☆216Updated 2 years ago
- Yet another variant of Process Hollowing☆355Updated 8 months ago