cocafe / physmemLinks
Physical memory and MMIO read/write command line utility via asmmap64 on Windows
☆18Updated 2 years ago
Alternatives and similar repositories for physmem
Users that are interested in physmem are comparing it to the libraries listed below
Sorting:
- Example of using Windows Platform Binary Table (WPBT)☆26Updated 2 years ago
- Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.☆86Updated 2 months ago
- An improved Detours.☆82Updated last month
- Another wow64ext to try to be compatible with WOW64 for all architectures.☆96Updated 2 months ago
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆78Updated 3 years ago
- Windows Kernel API wrapper with simplified functions and enterprise driver extensions.☆29Updated 3 months ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆84Updated 2 years ago
- Tiny C x86_64 function detouring library.☆24Updated last month
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆72Updated 2 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆52Updated 3 years ago
- Hypervisor-based debugger for AMD processors☆59Updated last year
- Fork of Scylla with additional fixes and Python bindings.☆52Updated last year
- ntdll.h - compatible with MSVC 6.0, Intel C++ Compiler and MinGW. Serves as a complete replacement for Windows.h☆146Updated 6 years ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆62Updated last year
- ☆51Updated 4 years ago
- Ghetto user mode emulation of Windows kernel drivers.☆149Updated last year
- Example WDF/KMDF driver and test app demonstrating the "inverted call model"☆37Updated 5 years ago
- x86-64 user mode emulation using Zydis☆69Updated last month
- "Mingw64 Driver Plus Plus": Mingw64, C++, DDK and (EA)STL made easy!☆42Updated last week
- Debug Print viewer (user and kernel)☆67Updated last year
- Kernel ReClassEx☆64Updated last year
- WinLicense key extraction via Intel PIN☆106Updated last year
- Cheat for my own game SecureGame which uses a bootkit to hyperjack Hyper-V in order to access VBS enclave's memory☆82Updated 10 months ago
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆49Updated last year
- An AI-powered assistant for IDA 9.0+ to accelerate reverse engineering of C++ games.☆188Updated last week
- Monitor Kernel pool allocations tags☆75Updated last year
- A plugin to x64dbg that lets you find out what writes to/accesses particular address☆115Updated 4 years ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆70Updated 3 years ago
- reverse engineering of the windows nt kernel debugger protocol & reimplementation.☆29Updated last year
- Simple EFI runtime driver that hooks GetVariable function and returns data expected by Windows to make it think that it's running with se…☆204Updated 4 years ago