i32-Sudo / EfiGuardUsermodeLoader
This is an EfiGuard BootLoader that can boot EfiGuard from Usermode with no USB or Setup as a Single Executable with automatic File Dumping using Bytes.
☆31Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for EfiGuardUsermodeLoader
- A simple kernel driver for R/W Using kSockets with some bypass implementation overall I wouldn't say its "ud"☆47Updated 2 months ago
- A Kernel Driver that can be used for a cheat or malware base to circumvent common cache & structure table checks. PsLoadedModuleList howe…☆75Updated 2 months ago
- My EAC & BE Rady CR3 Reading & Writing source that I use for my KM Drivers.☆44Updated 2 months ago
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆24Updated last month
- An Undetected BE Kernel Driver I developed, Will probably be detected upon releasing this but can be made undetected very easily. Does no…☆54Updated 2 months ago
- ☆49Updated 2 years ago
- This is a repo of my previous BEKernelDriver but updated to add better protections and a more detailed setup. also with a good bit of cod…☆55Updated 2 months ago
- Experiment with PAGE_GUARD protection to hide memory from other processes☆39Updated 5 months ago
- Kernel Level NMI Callback Blocker☆36Updated 2 months ago
- ntoskrnl .data hooks for UM-KM communication☆34Updated 5 months ago
- An Unsigned Driver Mapper for Windows 10 22H2 -> Windows 11 23H2 that uses PdFwKrnl to exploit the Read/Write IOCTL Calls to disable DSE …☆82Updated 2 months ago
- Virtual and physical memory hacking library using gigabyte vulnerable driver☆70Updated last year
- Injecting dll to protected games using ioclt and code cave communications, works on eac, be protected games but made for fn☆53Updated 7 months ago
- Read and Write process memory with this ioctl driver base. This is great for free cheats and learning kernel.☆49Updated 5 months ago
- ☆48Updated last year
- The sequel to Voyager☆20Updated 3 months ago
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆30Updated 8 months ago
- page table manipulation to gain physical r/w☆38Updated 6 months ago
- PoC kernel to usermode injection☆60Updated 8 months ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆80Updated last year
- ☆37Updated 4 months ago
- KDM Is a driver that will dumps every drivers that got manually mapped with kdmapper.☆48Updated 2 years ago
- Using c++23 compile-time magic to produce obfuscated PIC strings and arrays.☆15Updated 5 months ago
- ☆24Updated last month
- Execute anything in a legit memory region by attacking a windows driver☆20Updated last year
- clearing traces of a loaded driver☆44Updated 2 years ago
- Bypass using kernel driver (not finish).☆19Updated last year
- just proof of concept. hooking MmCopyMemory PG safe.☆63Updated last year
- ☆28Updated 8 months ago