googleprojectzero / bochspwn
A Bochs-based instrumentation project designed to log kernel memory references, to identify "double fetches" and other OS vulnerabilities
☆335Updated 6 years ago
Alternatives and similar repositories for bochspwn:
Users that are interested in bochspwn are comparing it to the libraries listed below
- A Bochs-based instrumentation performing kernel memory taint tracking to detect disclosure of uninitialized memory to ring 3☆301Updated 6 years ago
- Cross Platform Kernel Fuzzer Framework☆450Updated 6 years ago
- DynamoRIO plugin to get ASAN and SanitizerCoverage compatible output for closed-source executables☆207Updated 3 years ago
- ☆247Updated 4 years ago
- PEDA-like debugger UI for WinDbg☆203Updated last year
- Fuzzing the Kernel Using Unicornafl and AFL++☆300Updated 2 years ago
- ☆283Updated 5 years ago
- ☆179Updated 6 years ago
- Code for the USENIX 2017 paper: kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels☆579Updated 6 years ago
- Fuzz and Detect "Use After Free" vulnerability in win32k.sys ( Heap based )☆133Updated 9 years ago
- Improving AFL by using Intel PT to collect branch information☆292Updated 5 years ago
- Fuzzer for Linux Kernel Drivers☆378Updated 3 years ago
- Some kernel fuzzing paper about windows and linux☆255Updated 7 years ago
- Automatically exported from code.google.com/p/ioctlfuzzer☆162Updated 9 years ago
- Use angr in the IDA Pro debugger generating a state from the current debug session☆277Updated 4 years ago
- idahunt is a framework to analyze binaries with IDA Pro and hunt for things in IDA Pro☆386Updated last year
- A plugin for Hex-Ray's IDA Pro and radare2 to export the symbols recognized to the ELF symbol table☆208Updated 2 years ago
- Have fun with the LowFragmentationHeap☆239Updated 4 years ago
- CTF Challenge Framework for Windows 8 and above☆154Updated 3 years ago
- SALT - SLUB ALlocator Tracer for the Linux kernel☆151Updated 6 years ago
- AFL + DynamoRIO = fuzzing binaries with no source code on Linux☆248Updated 5 years ago
- Kernel driver to fuzz Hyper-V hypercalls☆137Updated 6 years ago
- HeapHopper is a bounded model checking framework for Heap-implementations☆216Updated 7 months ago
- A fuzzing tool for closed-source binaries based on Unicorn and LibFuzzer☆343Updated 5 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆434Updated 6 years ago
- American Fuzzy Lop + Dyninst == AFL Fuzzing blackbox binaries☆187Updated 3 years ago
- Tool to generate ROP gadgets for ARM, AARCH64, x86, MIPS, PPC, RISCV, SH4 and SPARC☆302Updated 8 months ago
- ☆197Updated 2 years ago
- SymGDB - symbolic execution plugin for gdb☆216Updated 6 years ago
- IDA script for highlighting and decoding ARM system instructions☆398Updated 3 years ago