ionescu007 / hazmat5
Local OXID Resolver (LCLOR) : Research and Tooling
☆33Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for hazmat5
- Command like tool to print mitigation flags for running processes in a memory dump☆44Updated 4 years ago
- ☆24Updated 11 months ago
- Helper idapython code for reversing kmdf drivers☆67Updated 2 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- ☆17Updated 3 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- Designed to learn OS specific anti-emulation patterns by fuzzing the Windows API.☆94Updated 4 years ago
- Sysmon shenanigans☆65Updated 4 years ago
- Winbindex bot to pull in binaries for specific releases☆46Updated last year
- ☆44Updated 4 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆50Updated 2 years ago
- ☆20Updated 3 years ago
- Windows kernel PDB data parsed into YAML☆31Updated last week
- An example of how x64 kernel shellcode can dynamically find and use APIs☆103Updated 4 years ago
- ☆19Updated 4 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆34Updated 4 years ago
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆85Updated 2 years ago
- ☆31Updated 4 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆69Updated last year
- ☆98Updated 2 years ago
- ☆10Updated 2 years ago
- A ready-made template for a project based on libpeconv.☆41Updated last month
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- Example for PagedOut!☆24Updated 5 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆28Updated 2 years ago
- "An Introduction to Windows Exploit Development" is an open sourced, free Windows exploit development course I created for the Southeast …☆39Updated 4 years ago
- Enabled / Disable LSA Protection via BYOVD☆62Updated 2 years ago