jjensn / CVE-2024-36877Links
Exploit POC for CVE-2024-36877
☆48Updated last year
Alternatives and similar repositories for CVE-2024-36877
Users that are interested in CVE-2024-36877 are comparing it to the libraries listed below
Sorting:
- Harness to issue Virtual Secure Mode (VSM) "secure calls" from VTL 0 to VTL 1☆70Updated 4 months ago
- Report and exploit of CVE-2023-36427☆90Updated 2 years ago
- Compact MBR Bootkit for Windows☆52Updated 4 years ago
- A simple but useful project maybe help you reverse Windows.☆41Updated last year
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆79Updated 3 years ago
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆34Updated 3 years ago
- Fuzzing Harness and Unpatched Crash Results from Fuzzing Defender MpEngine☆39Updated 6 months ago
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆38Updated last year
- Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)☆20Updated 5 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆67Updated 2 years ago
- Generate a PDB file given the old PDB file and an address mapping☆51Updated 5 months ago
- PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025☆60Updated 6 months ago
- A few examples of how to trap virtual memory access on Windows.☆39Updated last year
- Report and exploit of CVE-2024-21305.☆38Updated 2 years ago
- Different tools for Microsoft Hyper-V researching☆64Updated last month
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆38Updated 3 years ago
- Portable & Custmizable Windows Defender☆12Updated 4 years ago
- A fully compatible replacement of Windows NT NtCreateLowBoxToken syscall - precisely restored from reverse engineering☆42Updated 7 months ago
- An example of how to use Microsoft Windows Warbird technology☆30Updated 2 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆73Updated 2 years ago
- Elevate arbitrary MSR writes to kernel execution.☆43Updated 2 years ago
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆117Updated this week
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated 2 years ago
- WinHvShellcodeEmulator (WHSE) is a shellcode emulator leveraging the Windows Hypervisor Platform API☆26Updated 3 years ago
- Remove WPP calls from hexrays decompiled code☆54Updated 9 months ago
- ☆59Updated 3 years ago
- UEFI bootkit: Hardware Implant. In-Progress☆15Updated 3 years ago
- Reports and POCs for CVE 2024-43570 and CVE-2024-43535☆29Updated 7 months ago
- IDA plugin to recover source code from panic information on rust☆17Updated 8 months ago
- Abusing exceptions for code execution.☆113Updated 3 years ago