killvxk / uefi-rootkit
☆36Updated 3 years ago
Alternatives and similar repositories for uefi-rootkit
Users that are interested in uefi-rootkit are comparing it to the libraries listed below
Sorting:
- SMM UEFI module and client for UMD privilege escalation☆43Updated last year
- Another UEFI runtime bootkit☆30Updated 2 years ago
- Tool to dump EFI runtime drivers.☆35Updated last year
- EFI bootkit for loading unsigned drivers☆17Updated 10 months ago
- just proof of concept. hooking MmCopyMemory PG safe.☆70Updated last year
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆85Updated 7 months ago
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆60Updated last year
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆40Updated 11 months ago
- Guide for patching AMI Aptio V UEFI firmware to circumvent Secure Boot checks☆111Updated 10 months ago
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆37Updated 6 months ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆120Updated 2 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆184Updated last year
- Driver shared section communication☆50Updated 2 months ago
- Port of zentool to Windows☆24Updated 2 months ago
- Example of using Windows Platform Binary Table (WPBT)☆20Updated last year
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆59Updated last year
- x64 Windows implementation of virtual-address to physical-address translation☆42Updated 3 years ago
- A simple ida python script to find .data ptr☆51Updated 2 years ago
- Cheat for my own game SecureGame which uses a bootkit to hyperjack Hyper-V in order to access VBS enclave's memory☆55Updated 5 months ago
- intel vt-x type 2 hypervisor☆54Updated last month
- Win64 UEFI Driver-based tool for unrestricted memory R/W☆26Updated 3 years ago
- Using Windows' own bootloader as a shim to bypass Secure Boot☆169Updated 10 months ago
- nmi stackwalking + module verification☆115Updated last year
- Windows kernel driver template for cmkr (with testsigning).☆33Updated last year
- Old project (2020) reformed. Modifies gRT->GetVariable sub function from EFI_APPLICATION. Tested on Win10 22H2 (AMD).☆50Updated last year
- Reverse Engineering a signed kernel driver packed and virtualized with VMProtect 3.6☆102Updated 2 years ago
- detect hypervisor with Nmi Callback☆34Updated 2 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆52Updated 3 years ago
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆69Updated last year
- Windows PDB parser for kernel-mode environment.☆97Updated 2 years ago