nsacyber / Driver-Collider
Blocks drivers from loading by using a name collision technique. #nsacyber
☆45Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for Driver-Collider
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆59Updated 8 years ago
- ☆33Updated 7 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆75Updated 9 years ago
- A PowerShell module to assist in parsing and managing catalog files.☆20Updated 7 years ago
- Plugin for x64dbg to generate Yara rules from function basic blocks.☆35Updated 7 years ago
- ☆21Updated 3 years ago
- ☆45Updated 6 years ago
- Demos and presentation from SECArmy Village Grayhat 2020☆36Updated last year
- Malware Analysis, Anti-Analysis, and Anti-Anti-Analysis☆44Updated 7 years ago
- Blog posts☆30Updated 4 years ago
- All TMF files that I extracted from Microsoft PDBs.☆12Updated 5 years ago
- This tool is the result of a reverse engineering process of the Windows service called SysMain. Time to interact with the prefetch files …☆30Updated 4 years ago
- Parse Microsoft shim databases☆29Updated 2 months ago
- CAPE monitor DLLs☆38Updated 4 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆71Updated 5 years ago
- SentinelOne's KeRnel Exploits Advanced Mitigations☆52Updated 6 years ago
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆26Updated 6 years ago
- ☆61Updated 5 years ago
- findLoop - find possible encryption/decryption or compression/decompression code☆26Updated 5 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆50Updated 2 years ago
- Windows Drivers☆95Updated 5 years ago
- Decrement Windows Kernel for fun and profit☆39Updated 6 years ago
- Evil Reflective DLL Injection Finder☆45Updated 6 years ago
- Resources for the workshop titled "Repacking the unpacker: Applying Time Travel Debugging to malware analysis", given at HackLu 2019☆39Updated 5 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆54Updated 6 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆52Updated 8 months ago
- ☆21Updated 8 years ago