patrickmatula / Windows-Internals-Learning-Resources
☆100Updated 5 months ago
Alternatives and similar repositories for Windows-Internals-Learning-Resources:
Users that are interested in Windows-Internals-Learning-Resources are comparing it to the libraries listed below
- ☆105Updated 5 months ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 9 months ago
- ☆156Updated 11 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆98Updated last year
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆109Updated 7 months ago
- Exploit targeting NT kernel in 24H2 Windows Insider Preview☆129Updated 11 months ago
- Recon 2023 slides and code☆79Updated last year
- "Service-less" driver loading☆151Updated 4 months ago
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆92Updated this week
- Analyse MSI files for vulnerabilities☆129Updated 7 months ago
- ☆117Updated last year
- ☆105Updated 9 months ago
- ☆154Updated 4 months ago
- ☆113Updated 2 months ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆82Updated last year
- Windows rootkit designed to work with BYOVD exploits☆183Updated 3 months ago
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆134Updated last year
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated 2 months ago
- Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijac…☆212Updated 5 months ago
- Win32 keylogger that supports all (non-ime using) languages correctly☆49Updated last year
- kernel callback removal (Bypassing EDR Detections)☆161Updated last month
- PowerShell PE Parser☆62Updated 9 months ago
- C# Utilities for Windows Notification Facility☆150Updated last week
- Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process☆257Updated last year
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆141Updated 9 months ago
- ETW based POC to identify direct and indirect syscalls☆186Updated 2 years ago
- Admin to Kernel code execution using the KSecDD driver☆244Updated last year
- Local & remote Windows DLL Proxying☆164Updated 10 months ago
- CVE-2024-30090 - LPE PoC☆106Updated 6 months ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆198Updated 3 months ago