b-irb / PigPEI
PEIM (UEFI) bootkit targeting OVMF (EDK2)
☆34Updated last year
Alternatives and similar repositories for PigPEI:
Users that are interested in PigPEI are comparing it to the libraries listed below
- A VMWare logger using built-in backdoor.☆29Updated 6 months ago
- PDB Rewriting Rust Library☆23Updated 11 months ago
- A KISS Rust crate to parse Windows kernel crash-dumps created by Windows & its debugger.☆34Updated 2 months ago
- A minimalistic logger for Windows Kernel Drivers.☆22Updated last year
- Rust library for lifting raw binary data to LLVM IR☆47Updated last week
- Report and exploit of CVE-2024-21305.☆34Updated last year
- Rust bindings for VMProtect.☆25Updated last year
- Safe Rust bindings for the COM interfaces of the Windows debugging engine☆13Updated last month
- A few examples of how to trap virtual memory access on Windows.☆29Updated 3 months ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- An xtask to speed up Windows kernel driver development in rust.☆19Updated 9 months ago
- Generate a PDB file given the old PDB file and an address mapping☆44Updated last month
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆56Updated this week
- A demonstration of hooking into the VMProtect-2 virtual machine☆18Updated last year
- ☆16Updated 2 years ago
- ☆19Updated 2 years ago
- Sample Rust crate used to implement a VBS enclave in Rust☆18Updated last month
- Cargo subcommand to build a crate into shellcode☆24Updated 8 months ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆34Updated 6 months ago
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆38Updated 3 years ago
- Rule Engine for Dynamic Malware Analysis and Research☆18Updated this week
- A rust based DLL injection project☆30Updated 2 years ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆53Updated 2 years ago
- A set of LLVM and GCC based plugins that perform code obfuscation.☆122Updated last month
- Rust bindings to the System Informer's (formerly known as Process Hacker) "phnt" native Windows headers☆44Updated this week
- rekk is set of tools written in Rust to obfuscate ELF & PE executables with nanomites.☆31Updated 4 months ago
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆13Updated last year
- Finding Truth in the Shadows☆89Updated 2 years ago
- ☆38Updated 2 weeks ago