killvxk / uefi-rootkitLinks
☆41Updated 3 years ago
Alternatives and similar repositories for uefi-rootkit
Users that are interested in uefi-rootkit are comparing it to the libraries listed below
Sorting:
- SMM UEFI module and client for UMD privilege escalation☆65Updated 8 months ago
- Another UEFI runtime bootkit☆36Updated 2 years ago
- EFI bootkit for loading unsigned drivers☆29Updated last year
- SMM rootkit similar to LoJax or MosaicRegressor☆145Updated 2 years ago
- PoC that measures how long it takes the CPU to execute the CPUID instruction and reports if it suspects a VM. Works on both Windows and L…☆26Updated 5 years ago
- Tool to dump EFI runtime drivers.☆39Updated last year
- Autonomous pre-boot DMA attack hardware implant for M.2 slot based on PicoEVB development board☆101Updated 2 years ago
- Win64 UEFI Driver-based tool for unrestricted memory R/W☆30Updated 4 years ago
- Compact MBR Bootkit for Windows☆52Updated 4 years ago
- Example of using Windows Platform Binary Table (WPBT)☆27Updated 2 years ago
- Take back control of Windows Code Integrity, no exploits or patching required! Requires that you control your own Platform Key (PK).☆50Updated 3 years ago
- UEFI bootkit: Hardware Implant. In-Progress☆15Updated 3 years ago
- bypassing intel txt's tboot integrity checks via coreboot shim☆82Updated 10 months ago
- Hijacking Hyper-V at Runtime with DDMA☆76Updated 5 months ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆68Updated 2 years ago
- uefi diskless persistence technique + OVMF secureboot bypass☆95Updated last year
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆115Updated last year
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆122Updated this week
- Using Windows' own bootloader as a shim to bypass Secure Boot☆215Updated last year
- WinLicense key extraction via Intel PIN☆107Updated last year
- Runtime smm module loader☆35Updated 3 years ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆132Updated 2 years ago
- A Windows PE packer for executables (x64) with LZMA compression and with full TLS (Thread Local Storage) support.☆94Updated 3 months ago
- vdk is a set of utilities used to help with exploitation of a vulnerable driver.☆46Updated 3 years ago
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆60Updated last year
- Windows kernel driver template for cmkr (with testsigning).☆36Updated 2 years ago
- alternative smm driver for ryzen motherboards☆186Updated last year
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆38Updated last year
- Detects virtual machines and malware analysis environments☆146Updated 3 years ago
- 🪝 Various EPT hook detection approaches☆143Updated 6 months ago