ayoubfaouzi / windows-exploitation
My notes while studying Windows exploitation
☆187Updated last year
Alternatives and similar repositories for windows-exploitation:
Users that are interested in windows-exploitation are comparing it to the libraries listed below
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆123Updated last year
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆143Updated 2 years ago
- Exploit Development - Weaponized Exploit and Proof of Concepts (PoC)☆221Updated last year
- Recon 2023 slides and code☆79Updated last year
- Virus Exchange (VX) - Collection of malware or assembly code used for "offensive" purposed.☆180Updated 3 years ago
- A helper utility for creating shellcodes. Cleans MASM file generated by MSVC, gives refactoring hints.☆175Updated this week
- A curated list of awesome Windows Exploitation resources, and shiny things.☆73Updated 7 years ago
- Windows System Programming Experiments☆218Updated 2 years ago
- Set of antianalysis techniques found in malware☆132Updated last year
- Advanced driver monitoring utility.☆208Updated 2 years ago
- Kernel Exploits☆251Updated 3 years ago
- Important notes and topics on my journey towards mastering Windows Internals☆376Updated 11 months ago
- My notes while studying Windows internals☆425Updated 4 months ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆226Updated 2 years ago
- Yet another variant of Process Hollowing☆391Updated 3 months ago
- MalUnpack companion driver☆98Updated 10 months ago
- Windows Kernel Programming☆128Updated 4 years ago
- NINA: No Injection, No Allocation x64 Process Injection Technique☆219Updated 4 years ago
- ☆134Updated last month
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆278Updated 6 months ago
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆137Updated 2 years ago
- Source code of exploiting windows API for red teaming series☆148Updated 2 years ago
- Enumerating and removing kernel callbacks using signed vulnerable drivers☆558Updated 2 years ago
- ☆159Updated 3 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 9 months ago
- Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows☆207Updated 2 years ago
- A dynamic unpacking tool☆134Updated last year
- Yet another windows internals repo☆207Updated 3 years ago
- A comprehensive Hypervisor resources repo☆106Updated 2 months ago
- A library to develop kernel level Windows payloads for post HVCI era☆396Updated 3 years ago