googleprojectzero / bochspwn-reloaded
A Bochs-based instrumentation performing kernel memory taint tracking to detect disclosure of uninitialized memory to ring 3
☆297Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for bochspwn-reloaded
- A Bochs-based instrumentation project designed to log kernel memory references, to identify "double fetches" and other OS vulnerabilities☆325Updated 5 years ago
- DynamoRIO plugin to get ASAN and SanitizerCoverage compatible output for closed-source executables☆204Updated 3 years ago
- A hypervisor for fuzzing built with WHVP and Bochs☆367Updated 5 years ago
- Cross Platform Kernel Fuzzer Framework☆445Updated 6 years ago
- PEDA-like debugger UI for WinDbg☆201Updated 7 months ago
- ☆280Updated 4 years ago
- ☆238Updated 4 years ago
- Windows Kernel Drivers fuzzer☆296Updated 7 years ago
- idahunt is a framework to analyze binaries with IDA Pro and hunt for things in IDA Pro☆376Updated last year
- Fuzzing the Kernel Using Unicornafl and AFL++☆295Updated last year
- Fuzz and Detect "Use After Free" vulnerability in win32k.sys ( Heap based )☆132Updated 8 years ago
- Have fun with the LowFragmentationHeap☆232Updated 3 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆422Updated 6 years ago
- Automatically exported from code.google.com/p/ioctlfuzzer☆156Updated 9 years ago
- AFL + DynamoRIO = fuzzing binaries with no source code on Linux☆244Updated 5 years ago
- Some kernel fuzzing paper about windows and linux☆253Updated 7 years ago
- Code and exercises for a workshop on z3 and angr☆222Updated 3 years ago
- A curated list of Hyper-V exploitation resources, fuzzing and vulnerability research.☆389Updated 4 years ago
- ☆174Updated 5 years ago
- Windows RPC Python fuzzer☆156Updated 7 years ago
- Kernel driver to fuzz Hyper-V hypercalls☆135Updated 5 years ago
- Pocs for Antivirus Software‘s Kernel Vulnerabilities☆263Updated 7 years ago
- Use angr in the IDA Pro debugger generating a state from the current debug session☆268Updated 4 years ago
- The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by W…☆365Updated last year
- A fuzzing tool for closed-source binaries based on Unicorn and LibFuzzer☆342Updated 5 years ago
- Use angr inside GDB. Create an angr state from the current debugger state.☆199Updated 4 years ago
- ☆189Updated last year
- A user-friendly fuzzing and crash triage tool for Windows☆131Updated 4 years ago
- American Fuzzy Lop + Dyninst == AFL Fuzzing blackbox binaries☆186Updated 3 years ago
- Code for the USENIX 2017 paper: kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels☆573Updated 5 years ago