A Windows kernel driver viewer and manager built in Rust — real-time enumeration, signature verification, SCM operations, and multi-format exports with a modern dark-themed GUI.
☆155Mar 16, 2026Updated 6 months ago
Alternatives and similar repositories for DriverExplorer
Users that are interested in DriverExplorer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This repo contains PoCs for vulnerable Windows drivers.☆153Dec 20, 2025Updated 9 months ago
- Playing around with Thread Context Hijacking. Building more evasive primitives to use as alternative for existing process injection techn…☆209Jun 17, 2025Updated last year
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆261May 18, 2026Updated 4 months ago
- Blocking Windows EDR agents by registering an own IPC-object in the Object Manager’s namespace (CVE-2023-3280, CVE-2024-5909, CVE-2024-20…☆35Feb 27, 2025Updated last year
- This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.☆309May 23, 2026Updated 4 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Dynamic shellcode loader with sophisticated evasion capabilities☆343Oct 1, 2025Updated 11 months ago
- Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By…☆165Nov 23, 2025Updated 10 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated 3 months ago
- Dynamically resolve API function addresses at runtime in a secure manner.☆74Nov 11, 2025Updated 10 months ago
- PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads☆256Oct 30, 2025Updated 10 months ago
- Reports and POCs for CVE 2024-43570 and CVE-2024-43535☆31Jun 7, 2025Updated last year
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆134Dec 23, 2025Updated 9 months ago
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 3 months ago
- A lightweight Windows Prefetch file parser to extract programs' execution history☆70Jan 12, 2026Updated 8 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- indent guides plugin for hex-rays decompiler☆87Mar 10, 2026Updated 6 months ago
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆210Jun 25, 2026Updated 2 months ago
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 4 months ago
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆148Dec 8, 2025Updated 9 months ago
- Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.☆253Aug 4, 2026Updated last month
- Remote DLL Injection with Timer-based Shellcode Execution☆215Jul 18, 2025Updated last year
- The different ways to dump lsass☆289Jul 19, 2026Updated 2 months ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆293Jun 22, 2026Updated 3 months ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55Sep 15, 2026Updated last week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- debug isolated usermode process on Nested Virtualization guest vm☆34Oct 20, 2025Updated 11 months ago
- Intel 64/Windows low-level experiments☆118Sep 16, 2026Updated last week
- An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts☆161Jul 7, 2026Updated 2 months ago
- Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.☆101Apr 30, 2026Updated 4 months ago
- AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64☆564Mar 7, 2026Updated 6 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆508Mar 15, 2026Updated 6 months ago
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆114Jul 14, 2026Updated 2 months ago
- Encode shellcode as XML-looking data. Single-header C library with a two-stage PIC loader example.☆15Feb 11, 2026Updated 7 months ago
- Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption☆233Dec 17, 2025Updated 9 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Implementation of hello world in windows, focusing on binary size and malleability of windows binaries☆18Jul 3, 2025Updated last year
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆420Sep 3, 2026Updated 2 weeks ago
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆117Jan 20, 2025Updated last year
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆48Jan 25, 2025Updated last year
- ☆45Oct 10, 2025Updated 11 months ago
- Combining KslDump and GhostKatz to dump LSASS using no-vulnerability KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WD…☆10Jul 6, 2026Updated 2 months ago
- Extract Windows credentials directly from VM memory snapshots and virtual disks☆1,584Jun 7, 2026Updated 3 months ago