A Windows kernel driver viewer and manager built in Rust — real-time enumeration, signature verification, SCM operations, and multi-format exports with a modern dark-themed GUI.
☆154Mar 16, 2026Updated 4 months ago
Alternatives and similar repositories for DriverExplorer
Users that are interested in DriverExplorer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This repo contains PoCs for vulnerable Windows drivers.☆153Dec 20, 2025Updated 7 months ago
- Playing around with Thread Context Hijacking. Building more evasive primitives to use as alternative for existing process injection techn…☆207Jun 17, 2025Updated last year
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browser…☆254May 18, 2026Updated 2 months ago
- Blocking Windows EDR agents by registering an own IPC-object in the Object Manager’s namespace (CVE-2023-3280, CVE-2024-5909, CVE-2024-20…☆37Feb 27, 2025Updated last year
- Dynamic shellcode loader with sophisticated evasion capabilities☆342Oct 1, 2025Updated 9 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By…☆164Nov 23, 2025Updated 7 months ago
- This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.☆301May 23, 2026Updated last month
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆40Jun 4, 2026Updated last month
- A lightweight Windows Prefetch file parser to extract programs' execution history☆70Jan 12, 2026Updated 6 months ago
- PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads☆257Oct 30, 2025Updated 8 months ago
- Windows security research toolkit for LPE, persistence, COM hijacking, and attack surface enumeration.☆205Jun 13, 2026Updated last month
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆210Jun 25, 2026Updated 3 weeks ago
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 2 months ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆130Dec 23, 2025Updated 6 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Reports and POCs for CVE 2024-43570 and CVE-2024-43535☆31Jun 7, 2025Updated last year
- Evade behavioral analysis by executing malicious code within trusted Microsoft call stacks, patchless hooking library IAT/EAT.☆146Dec 8, 2025Updated 7 months ago
- Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.☆243Jun 11, 2026Updated last month
- Intel 64/Windows low-level experiments☆105Jun 7, 2026Updated last month
- indent guides plugin for hex-rays decompiler☆89Mar 10, 2026Updated 4 months ago
- Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.☆98Apr 30, 2026Updated 2 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated last month
- An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts☆157Jul 7, 2026Updated 2 weeks ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆273Jun 22, 2026Updated 3 weeks ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- The different ways to dump lsass☆289Updated this week
- AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64☆543Mar 7, 2026Updated 4 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆508Mar 15, 2026Updated 4 months ago
- Remote DLL Injection with Timer-based Shellcode Execution☆216Jul 18, 2025Updated last year
- debug isolated usermode process on Nested Virtualization guest vm☆34Oct 20, 2025Updated 9 months ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55May 15, 2026Updated 2 months ago
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆410Updated this week
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆89Updated this week
- A PoC Cobalt Strike UDRL written in Rust☆32Jun 20, 2026Updated last month
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Encode shellcode as XML-looking data. Single-header C library with a two-stage PIC loader example.☆15Feb 11, 2026Updated 5 months ago
- Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption☆231Dec 17, 2025Updated 7 months ago
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆236May 23, 2026Updated last month
- Lab research on Windows loader internals, PE loading, stack artifacts, and execution tradeoffs.☆237May 4, 2026Updated 2 months ago
- Implementation of hello world in windows, focusing on binary size and malleability of windows binaries☆18Jul 3, 2025Updated last year
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆117Jan 20, 2025Updated last year
- Extract Windows credentials directly from VM memory snapshots and virtual disks☆1,421Jun 7, 2026Updated last month