clymb3r / KdExploitMe
A kernel driver to practice writing exploits against, as well as some example exploits using public techniques.
☆403Updated 10 years ago
Alternatives and similar repositories for KdExploitMe:
Users that are interested in KdExploitMe are comparing it to the libraries listed below
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆389Updated 5 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆430Updated 6 years ago
- C++ application that uses memory and code hooks to detect packers☆270Updated 7 years ago
- flare-dbg is a project meant to aid malware reverse engineers in rapidly developing debugger scripts.☆150Updated 7 years ago
- Pocs for Antivirus Software‘s Kernel Vulnerabilities☆263Updated 7 years ago
- Content from presentation at BHUSA 2017☆180Updated 7 years ago
- ATrace is a tool for tracing execution of binaries on Windows.☆237Updated 8 years ago
- A tool to detect and crash Cuckoo Sandbox☆292Updated 8 months ago
- ROPMEMU is a framework to analyze, dissect and decompile complex code-reuse attacks.☆284Updated 8 years ago
- Fuzz and Detect "Use After Free" vulnerability in win32k.sys ( Heap based )☆132Updated 9 years ago
- Python scripts for reverse engineering.☆182Updated 3 years ago
- Windows XP 32-Bit Bootkit☆144Updated 10 years ago
- HORSEPILL rootkit PoC☆225Updated 8 years ago
- PowerLoaderEx - Advanced Code Injection Technique for x32 / x64☆362Updated 7 years ago
- I Know Where Your Page Lives: Derandomizing the latest Windows 10 Kernel - ZeroNights 2016☆163Updated 8 years ago
- Small tool for generating ropchains using unicorn and z3☆197Updated 7 years ago
- Loading unsigned code into kernel in Windows 10 (64) with help of VMware Workstation Pro/Player design flaw☆135Updated 7 years ago
- Zerokit/GAPZ rootkit (non buildable and only for researching)☆182Updated 5 years ago
- Automatically exported from code.google.com/p/ioctlfuzzer☆160Updated 9 years ago
- Bunch of techniques potentially used by malware to detect analysis environments☆158Updated 8 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆359Updated 5 years ago
- ☆232Updated 7 years ago
- Patching ROP-encoded shellcodes into PEs☆184Updated 7 years ago
- DC25 5A1F - Demystifying Windows Kernel Exploitation by Abusing GDI Objects☆145Updated 7 years ago
- heaper, an advanced heap analysis plugin for Immunity Debugger☆96Updated 12 years ago
- Cminer is a tool for enumerating the code caves in PE files.☆148Updated last year
- IDA Sploiter is a plugin for Hex-Ray's IDA Pro disassembler designed to enhance IDA's capabilities as an exploit development and vulnerab…☆188Updated 5 years ago
- PEI stage backdoor for UEFI compatible firmware☆219Updated 3 years ago
- A set of tutorials about code injection for Windows.☆311Updated 6 months ago
- ☆140Updated 7 years ago