Windows kernel research tool. Looks like a debugger, but it is not a debugger. It uses a kernel driver to provide a WinDbg-like live kernel debugging experience from a TUI console.
☆73Sep 20, 2026Updated last week
Alternatives and similar repositories for kn-live-dbg
Users that are interested in kn-live-dbg are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts☆162Jul 7, 2026Updated 2 months ago
- WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.☆111Jun 22, 2026Updated 3 months ago
- Modern Win32 API monitor for Windows security, reverse engineering, debugging, and anti-cheat research.☆51Sep 21, 2026Updated last week
- ApplyCalleeType IDA Plugin 🤙 — Reborn. Single-file port to IDA Pro 9.3 with right-click menu, live prototype editor, and full SAL/MSDN p…☆83Mar 9, 2026Updated 6 months ago
- Kernforge is a project intelligence and fuzzing workbench for Windows security, anti-cheat engineering, and evidence-backed verification.☆25Jul 23, 2026Updated 2 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Windows Analysis and Research Toolkit☆696Apr 28, 2026Updated 5 months ago
- Intel 64/Windows low-level experiments☆118Sep 16, 2026Updated 2 weeks ago
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆94Mar 16, 2026Updated 6 months ago
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆33Sep 1, 2026Updated last month
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆205Apr 27, 2026Updated 5 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆86Dec 21, 2022Updated 3 years ago
- Lua bytecode disassembler and decompiler for Lua 5.1, 5.2, 5.3, 5.4, and 5.5 binary chunks.☆35May 18, 2026Updated 4 months ago
- Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reacha…☆67Feb 26, 2026Updated 7 months ago
- ☆28Jun 21, 2026Updated 3 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- An educational anti-cheat system for learning Windows kernel programming, process monitoring, and cheat detection techniques☆44Jul 24, 2026Updated 2 months ago
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆159Jul 15, 2026Updated 2 months ago
- Thats it! An Open-Source Windows UEFI Rootkit☆41Jul 19, 2025Updated last year
- This repository contains the research tool presented at x33fcon 2026, along with the associated presentation slides. The content is made …☆65Jun 15, 2026Updated 3 months ago
- tests to catch some sloppy hv impls☆36Mar 16, 2026Updated 6 months ago
- binary instrumentation, analysis, and patching framework☆104Feb 20, 2026Updated 7 months ago
- first public in-process reflective PE loader for .NET NativeAOT binaries. maps a NativeAOT executable into the current process and execut…☆28Mar 28, 2026Updated 6 months ago
- usermode thread hijacking detection via working set page fault monitoring☆43Jul 17, 2026Updated 2 months ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Multiplatform MEMORY.DMP analysis tool with a WinDbg flavor☆176Apr 20, 2026Updated 5 months ago
- Ctrl+Scroll font zoom for all IDA views — Disassembly, Pseudocode, Hex View, Imports, Exports, Functions, Strings, and more. Compatible I…☆31Apr 15, 2026Updated 5 months ago
- Set of PoC to abuse Windows minifilters functionality☆94May 1, 2026Updated 5 months ago
- ☆88Feb 12, 2026Updated 7 months ago
- Hooking Windows' exception dispatcher to protect process's PML4☆273Jan 24, 2025Updated last year
- ☆32Apr 2, 2026Updated 6 months ago
- Static devirtualizer for VMProtect 3.0-3.5. Lifts virtualized code to LLVM using Remill and strips the VM layer through optimization.☆316Jul 30, 2026Updated 2 months ago
- Injecting code by recompiling shellcode into a ROP chain.☆148Apr 21, 2026Updated 5 months ago
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆210Jun 25, 2026Updated 3 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- stack based arithmetic only virtual machine (VM) executes bytecode instructions to perform various basic arithmetic operations and manage…☆27Mar 19, 2025Updated last year
- WinDbg plugin to trace module transitions from a debugged driver.☆53Dec 22, 2025Updated 9 months ago
- A sleepmask based on Ekko that preserves unwind data at sleep time.☆56Mar 30, 2026Updated 6 months ago
- A cross-platform C++ framework for building Windows shellcode☆178Sep 14, 2026Updated 2 weeks ago
- Vibe Reverse Engineer with IDA SQL: An interface for IDA in SQL via live virtual tables☆409Jul 26, 2026Updated 2 months ago
- Harness to issue Virtual Secure Mode (VSM) "secure calls" from VTL 0 to VTL 1☆87Sep 8, 2025Updated last year
- C# MCP server for kernel & user-mode Windows debugging — DbgEng COM, KDNET, Frida, dbgsrv, TTD, and integrated VM control. 29 tools for L…☆41Updated this week