dmaivel / ntoseye
Windows kernel debugger for Linux hosts running Windows under KVM/QEMU
☆80Updated 6 months ago
Alternatives and similar repositories for ntoseye:
Users that are interested in ntoseye are comparing it to the libraries listed below
- bypassing intel txt's tboot integrity checks via coreboot shim☆66Updated last month
- Report and exploit of CVE-2024-21305.☆34Updated last year
- Generate a PDB file given the old PDB file and an address mapping☆48Updated 2 months ago
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆117Updated 6 months ago
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆152Updated 2 months ago
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆114Updated last year
- A large collection of 32bit and 64bit PE files useful for verifying the correctness of bin2bin transformations☆52Updated 9 months ago
- uefi diskless persistence technique + OVMF secureboot bypass☆61Updated last year
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- Plugin interface for remote communications with Binary Ninja database and MCP server for interfacing with LLMs.☆32Updated this week
- A set of LLVM and GCC based plugins that perform code obfuscation.☆123Updated 2 months ago
- Report and exploit of CVE-2023-36427☆90Updated last year
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆79Updated 9 months ago
- Hyper-V related resources☆30Updated last year
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆34Updated 7 months ago
- All LLVM binaries scrambled with SigBreaker and used to test against llvm-lit☆14Updated 3 weeks ago
- A journal for $6,000 Riot Vanguard bounty.☆63Updated last year
- A curated list of awesome resources related to anti virtualization techniques☆47Updated 3 weeks ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆136Updated 8 months ago
- ☆87Updated 11 months ago
- An x86-64 code virtualizer for VM based obfuscation☆119Updated 4 months ago
- compile-time control flow obfuscation using mba☆182Updated last year
- Proof-of-concept game using VBS enclaves to protect itself from cheating☆40Updated 6 months ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆64Updated last year
- Binary rewriter for 64-bit PE files.☆71Updated last year
- Abusing exceptions for code execution.☆110Updated 2 years ago
- Different tools for Microsoft Hyper-V researching☆57Updated 11 months ago
- Rust library for lifting raw binary data to LLVM IR☆50Updated 3 weeks ago
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆92Updated 6 months ago
- Finding Truth in the Shadows☆92Updated 2 years ago