killvxk / uefi-rootkit
☆34Updated 2 years ago
Alternatives and similar repositories for uefi-rootkit:
Users that are interested in uefi-rootkit are comparing it to the libraries listed below
- Another UEFI runtime bootkit☆29Updated last year
- Tool to dump EFI runtime drivers.☆35Updated 11 months ago
- EFI bootkit for loading unsigned drivers☆17Updated 7 months ago
- Windows PDB parser for kernel-mode environment.☆94Updated 2 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆176Updated last year
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆41Updated 8 months ago
- A intel hypervisor, implementing many virtualization techniques☆39Updated last year
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆49Updated last year
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆113Updated last year
- just proof of concept. hooking MmCopyMemory PG safe.☆64Updated last year
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆81Updated 4 months ago
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆71Updated last year
- A simple ida python script to find .data ptr☆49Updated last year
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆36Updated 4 months ago
- Shows an example of how to implement VT-d/AMD-Vi on Windows☆99Updated last year
- ☆28Updated 4 months ago
- nmi stackwalking + module verification☆104Updated last year
- SMM UEFI module and client for UMD privilege escalation☆32Updated last year
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆51Updated 2 years ago
- intel vt-x type 2 hypervisor☆49Updated 8 months ago
- Kernel ReClassEx☆65Updated last year
- Old project (2020) reformed. Modifies gRT->GetVariable sub function from EFI_APPLICATION. Tested on Win10 22H2 (AMD).☆46Updated 11 months ago
- DSE & PG bypass via BYOVD attack☆42Updated 10 months ago
- ☆137Updated this week
- Driver that communicates using a thread and a shared section with Usermode☆38Updated last week
- ☆41Updated 3 years ago
- detect hypervisor with Nmi Callback☆34Updated 2 years ago
- Experiment with PAGE_GUARD protection to hide memory from other processes☆45Updated 7 months ago
- Kernel Level NMI Callback Blocker☆64Updated 5 months ago
- ☆50Updated 2 years ago