My notes while studying Windows exploitation
☆194Mar 27, 2026Updated 5 months ago
Alternatives and similar repositories for windows-exploitation
Users that are interested in windows-exploitation are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- My notes while studying Windows internals☆493Jul 6, 2026Updated last month
- Intel / AMD CPU Internals☆1,208Jun 24, 2026Updated 2 months ago
- "An Introduction to Windows Exploit Development" is an open sourced, free Windows exploit development course I created for the Southeast …☆40Apr 17, 2020Updated 6 years ago
- A C++ syscall ID extractor for Windows. Developed, debugged and tested on 20H2.☆22May 25, 2021Updated 5 years ago
- Analyze Windows x64 Kernel Memory Layout☆134Nov 19, 2020Updated 5 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆244Nov 6, 2019Updated 6 years ago
- Kernel Detective☆154May 24, 2026Updated 3 months ago
- Offensive Assembly code snippets.☆15Jul 12, 2023Updated 3 years ago
- The Win32 Anti-Intrusion Library☆216May 30, 2019Updated 7 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆645Jul 7, 2017Updated 9 years ago
- createfile☆48Oct 27, 2015Updated 10 years ago
- Various methods of executing shellcode☆75Mar 27, 2023Updated 3 years ago
- This is a collection of interesting codes about Windows Process creation.☆239Jan 12, 2024Updated 2 years ago
- Kernel-Mode Driver that loads a dll into every new created process that loads kernel32.dll module☆423Sep 9, 2018Updated 7 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆244Sep 26, 2023Updated 2 years ago
- A process overwriting its own PEB to make an illusion that it has been loaded from a different path.☆99Jun 24, 2021Updated 5 years ago
- Collect different versions of Crucial modules.☆148Jul 11, 2024Updated 2 years ago
- Bypassing PatchGuard on modern x64 systems☆268Apr 9, 2023Updated 3 years ago
- Application Verifier Dynamic Fault Injection☆42Aug 18, 2026Updated last week
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆154Feb 23, 2019Updated 7 years ago
- NASM listing to shellcode converter☆14May 6, 2018Updated 8 years ago
- LDE64 (relocatable) source code☆103Jun 24, 2015Updated 11 years ago
- windows rootkit☆60May 2, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Analysing and defeating PatchGuard universally☆34Nov 4, 2020Updated 5 years ago
- Simple driver to register all available process, thread, image, Registry, and Object callbacks☆123Oct 5, 2017Updated 8 years ago
- Small driver that uses alternative syscalls feature☆17May 9, 2024Updated 2 years ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆68May 11, 2023Updated 3 years ago
- Intel Virtualization Technology demo☆71Oct 15, 2016Updated 9 years ago
- Simple program for static hooking dynamic libraries in executable application☆24Jan 15, 2014Updated 12 years ago
- Abusing exceptions for code execution.☆110Jan 30, 2023Updated 3 years ago
- Signtool for expired certificates☆525Jun 10, 2023Updated 3 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆82Jan 24, 2011Updated 15 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Research on Windows Kernel Executive Callback Objects☆315Feb 22, 2020Updated 6 years ago
- Page fault hook use ept (Intel Virtualization Technology)☆198Oct 19, 2016Updated 9 years ago
- Windows system repair tool☆18Jun 2, 2021Updated 5 years ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆68May 2, 2023Updated 3 years ago
- Static library and headers for linking your software with ntdll.dll☆38Dec 16, 2019Updated 6 years ago
- Useful scripts for WinDbg using the debugger data model☆436Mar 27, 2024Updated 2 years ago
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆420Jul 6, 2022Updated 4 years ago