This repo contains PoCs for vulnerable Windows drivers.
☆153Dec 20, 2025Updated 7 months ago
Alternatives and similar repositories for WinDriver-EXP
Users that are interested in WinDriver-EXP are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Reports and POCs for CVE 2024-43570 and CVE-2024-43535☆31Jun 7, 2025Updated last year
- Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By…☆164Nov 23, 2025Updated 8 months ago
- Kernel Information Disclosure☆35Jan 13, 2026Updated 6 months ago
- BYOVD: Use 360 WFP driver to block EDR/XDR network connection.☆128Feb 10, 2026Updated 5 months ago
- This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.☆302May 23, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A Windows kernel driver viewer and manager built in Rust — real-time enumeration, signature verification, SCM operations, and multi-for…☆154Mar 16, 2026Updated 4 months ago
- Identifies LOLDrivers that are not blocked by the active HVCI policy — ideal for BYOVD scenarios.☆91Jul 25, 2025Updated 11 months ago
- This tool helps inject code into the processes of Antivirus programs.☆189May 23, 2026Updated 2 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆192Apr 27, 2026Updated 2 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆237May 23, 2026Updated 2 months ago
- Querying And Deleting Shadow Copies Using The IOCTL_VOLSNAP_QUERY_NAMES_OF_SNAPSHOTS & IOCTL_VOLSNAP_DELETE_SNAPSHOT IOCTLs☆22Aug 7, 2025Updated 11 months ago
- AppLocker-Based EDR Neutralization☆340Dec 19, 2025Updated 7 months ago
- Just another EDR killer☆141Jan 21, 2026Updated 6 months ago
- Windows Session Hijacking via COM☆349Dec 13, 2025Updated 7 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Bof of RegPwn by MDSec☆127Mar 15, 2026Updated 4 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 4 months ago
- Enumerate active EDR's on the system☆153Sep 23, 2025Updated 10 months ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- NSecSoftBYOVD POC☆61Feb 12, 2026Updated 5 months ago
- Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls☆284Jul 13, 2026Updated last week
- Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection☆75Dec 26, 2025Updated 6 months ago
- PoC for popping a system shell against the LnvMSRIO.sys driver☆124Oct 6, 2025Updated 9 months ago
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆254May 18, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Dumping App Bound Protected Credentials & Cookies Without Privileges.☆168May 28, 2025Updated last year
- Obex – Blocking unwanted DLLs in user mode☆279Sep 18, 2025Updated 10 months ago
- A critical RCE vulnerability in Windows TCP/IP stack (CVE-2025-26686) leaves sensitive memory unlocked, allowing remote attackers to hija…☆31Sep 16, 2025Updated 10 months ago
- Windows rootkit designed to work with BYOVD exploits☆224Jan 18, 2025Updated last year
- Python script that fetches, analyzes, and reports Microsoft Patch Tuesday updates via the MSRC API — with a clean web interface for easy …☆28Updated this week
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆194May 23, 2026Updated 2 months ago
- SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connecti…☆454Nov 3, 2025Updated 8 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆336Feb 2, 2026Updated 5 months ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆386Dec 13, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A Windows Named Pipe Multi-tool / Proxy☆359Dec 7, 2025Updated 7 months ago
- Proof-of-Concept exploit for CVE-2026-32223☆21Apr 17, 2026Updated 3 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆469Jun 18, 2026Updated last month
- Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation …☆124Feb 19, 2026Updated 5 months ago
- **CVE-2026-2636** is a vulnerability in the Windows Common Log File System (CLFS) driver (`CLFS.sys`). An unprivileged user can trigger a…☆15Feb 26, 2026Updated 4 months ago
- Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan …☆216Dec 8, 2025Updated 7 months ago
- A simple POC to show how to chain multiple callbacks via tail calls to artificially construct a call stack☆109May 25, 2026Updated last month