memN0ps / illusion-rs
Rusty Hypervisor - Windows UEFI Blue Pill Type-1 Hypervisor in Rust (Codename: Illusion)
☆247Updated 4 months ago
Alternatives and similar repositories for illusion-rs:
Users that are interested in illusion-rs are comparing it to the libraries listed below
- x86-64 code/pe virtualizer☆176Updated last month
- Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)☆268Updated 6 months ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆274Updated last year
- Collection of hypervisor detections☆213Updated 3 months ago
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆190Updated 2 months ago
- AMD Hypervisor written writh Rust.☆137Updated last year
- Native code virtualizer for x64 binaries☆457Updated 3 weeks ago
- ☆128Updated last month
- Debugger Anti-Detection Benchmark☆302Updated last year
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆168Updated last year
- x86-64 virtualizing obfuscator written in Rust☆69Updated last year
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆269Updated 3 months ago
- RISC-V Virtual Machine☆212Updated 3 weeks ago
- Memory hacking library powered by AMD SVM☆315Updated last year
- compile-time control flow obfuscation using mba☆176Updated last year
- Kernel driver for detecting Intel VT-x hypervisors.☆174Updated last year
- A bare minimum hypervisor on AMD and Intel processors for learners.☆223Updated 2 weeks ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆338Updated 2 months ago
- Minimalistic AMD-V/SVM hypervisor with memory introspection capabilities☆193Updated 7 months ago
- ☆84Updated 7 months ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆124Updated 4 months ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆243Updated 2 years ago
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆133Updated 2 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆120Updated 3 years ago
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆78Updated 3 months ago
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆115Updated 2 months ago
- Browse Page Tables on Windows (Page Table Viewer)☆194Updated 2 years ago
- alternative smm driver for ryzen motherboards☆112Updated 3 months ago
- Tool to dump UEFI runtime drivers implementing runtime services for Windows☆95Updated 4 years ago
- A mapper that maps shellcode into loaded large page drivers☆245Updated 2 years ago