cocafe / physmemLinks
Physical memory and MMIO read/write command line utility via asmmap64 on Windows
☆17Updated 2 years ago
Alternatives and similar repositories for physmem
Users that are interested in physmem are comparing it to the libraries listed below
Sorting:
- Example of using Windows Platform Binary Table (WPBT)☆26Updated 2 years ago
- Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.☆90Updated 2 months ago
- Tiny C x86_64 function detouring library.☆24Updated 2 months ago
- Hypervisor-based debugger for AMD processors☆59Updated last year
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆78Updated 3 years ago
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆49Updated last year
- Another wow64ext to try to be compatible with WOW64 for all architectures.☆98Updated 3 months ago
- Class Informer updated for 32bit targets in 64bit IDA 8.2+/9.0/9.1☆62Updated 7 months ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆83Updated 2 years ago
- Monitor Kernel pool allocations tags☆76Updated 2 years ago
- Proof of concept for injecting a 64-bit DLL into a 32-bit application☆43Updated 2 years ago
- WinLicense key extraction via Intel PIN☆107Updated last year
- Simple and lightweight hypervisor for AMD processors☆41Updated 3 weeks ago
- Windows driver mapper via the UEFI☆48Updated 4 months ago
- Windows PDB parser for kernel-mode environment.☆101Updated 5 months ago
- VMProtect2 Deobfuscation Tooling☆63Updated last week
- https://www.codeproject.com/Articles/5348168/Disable-Driver-Signature-Enforcement-with-DSE-Patc☆20Updated 2 years ago
- Windows Kernel API wrapper with simplified functions and enterprise driver extensions.☆29Updated 4 months ago
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆73Updated 2 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆51Updated 3 years ago
- "Mingw64 Driver Plus Plus": Mingw64, C++, DDK and (EA)STL made easy!☆42Updated last month
- The bootloader for the latest versions of Windows NT, Windows 8 to Windows 11.☆24Updated 5 years ago
- A bunch of architectural headers for i386 and AMD64☆40Updated 2 years ago
- reverse engineering of the windows nt kernel debugger protocol & reimplementation.☆29Updated last year
- Native API header files for the Process Hacker project (nightly).☆25Updated last month
- Intraceptor intercept Windows NT API calls and redirect them to a kernel driver to bypass process/threads handle protections.☆32Updated 3 years ago
- An improved Detours.☆86Updated 2 weeks ago
- Win64 UEFI Driver-based tool for unrestricted memory R/W☆29Updated 3 years ago
- KDP compatible unsigned driver loader leveraging a write primitive in one of the IOCTLs of gdrv.sys☆162Updated last year
- Debug Print viewer (user and kernel)☆69Updated last year