pmatula / Windows-Internals-Learning-Resources
☆94Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for Windows-Internals-Learning-Resources
- ☆95Updated last week
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆109Updated 3 months ago
- ☆152Updated 5 months ago
- Recon 2023 slides and code☆78Updated last year
- ☆104Updated this week
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆131Updated 10 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆95Updated 6 months ago
- Tools for analyzing EDR agents☆208Updated 5 months ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆65Updated last year
- Admin to Kernel code execution using the KSecDD driver☆237Updated 6 months ago
- ☆103Updated 3 months ago
- Analyse MSI files for vulnerabilities☆108Updated 2 months ago
- PowerShell PE Parser☆61Updated 4 months ago
- Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths☆296Updated 2 months ago
- Exploit targeting NT kernel in 24H2 Windows Insider Preview☆111Updated 6 months ago
- ☆140Updated 3 months ago
- Python tool to check rootkits in Windows kernel☆165Updated 3 months ago
- A collection of tools, scripts and personal research☆111Updated 4 months ago
- A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files …☆124Updated 3 months ago
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆324Updated 5 months ago
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆300Updated last year
- This comprehensive process injection series is crafted for cybersecurity enthusiasts, researchers, and professionals who aim to stay at t…☆239Updated last week
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆79Updated 8 months ago
- Aplos an extremely simple fuzzer for Windows binaries.☆66Updated 7 months ago
- ☆130Updated last year
- This comprehensive and central repository is designed for cybersecurity enthusiasts, researchers, and professionals seeking to stay ahead…☆75Updated last week
- Payload encoding utility to effectively lower payload entropy.☆90Updated last month
- Generate a proxy dll for arbitrary dll☆138Updated 3 weeks ago
- ☆101Updated 9 months ago
- Contains all the applications developed for the Second part of the 7th Edition of Windows Internals book☆101Updated 4 months ago