cocafe / physmemLinks
Physical memory and MMIO read/write command line utility via asmmap64 on Windows
☆18Updated 2 years ago
Alternatives and similar repositories for physmem
Users that are interested in physmem are comparing it to the libraries listed below
Sorting:
- Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.☆96Updated 5 months ago
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆79Updated 3 years ago
- Hypervisor-based debugger for AMD processors☆63Updated last year
- Example of using Windows Platform Binary Table (WPBT)☆26Updated 2 years ago
- Windows Kernel API wrapper with simplified functions and enterprise driver extensions.☆31Updated 7 months ago
- An improved Detours.☆104Updated 2 weeks ago
- Debug Print viewer (user and kernel)☆71Updated 2 years ago
- reverse engineering of the windows nt kernel debugger protocol & reimplementation.☆36Updated last year
- ☆51Updated 5 years ago
- "Mingw64 Driver Plus Plus": Mingw64, C++, DDK and (EA)STL made easy!☆43Updated 3 months ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆83Updated 2 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆53Updated 3 years ago
- Windows PDB parser for kernel-mode environment.☆103Updated 8 months ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆67Updated 2 years ago
- The bootloader for the latest versions of Windows NT, Windows 8 to Windows 11.☆26Updated 5 years ago
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆53Updated last year
- Another wow64ext to try to be compatible with WOW64 for all architectures.☆98Updated last month
- ntdll.h - compatible with MSVC 6.0, Intel C++ Compiler and MinGW. Serves as a complete replacement for Windows.h☆149Updated 6 years ago
- Example WDF/KMDF driver and test app demonstrating the "inverted call model"☆37Updated 5 years ago
- Proof of concept for injecting a 64-bit DLL into a 32-bit application☆47Updated 2 years ago
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆75Updated 2 years ago
- Windows Research Kernel☆37Updated 4 months ago
- InfinityHookProMax: Make InfinityHook great great again☆51Updated 2 years ago
- Disables virtualprotect checks/hooks so you can modify memory and change memory protection in binaries protected by VMProtect.☆135Updated 4 years ago
- Global DLL injector☆71Updated 4 years ago
- Load vulnerable drivers using iqvw64e.sys hijack☆36Updated 2 years ago
- Tiny C x86_64 function detouring library.☆28Updated 2 weeks ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆47Updated 2 years ago
- Guide for patching AMI Aptio V UEFI firmware to circumvent Secure Boot checks☆131Updated last year
- x64 Windows implementation of virtual-address to physical-address translation☆46Updated 4 years ago