Binary Ninja plugin to perform automated analysis of Windows drivers
☆20Aug 8, 2019Updated 6 years ago
Alternatives and similar repositories for driveranalyzer
Users that are interested in driveranalyzer are comparing it to the libraries listed below
Sorting:
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Aug 11, 2023Updated 2 years ago
- Data and structures regarding the research done on WdFilter☆12Apr 15, 2020Updated 5 years ago
- a tiny code that performs kernel-mode read/write using CVE-2023-38817.☆18Mar 28, 2025Updated 11 months ago
- ☆19Dec 28, 2021Updated 4 years ago
- Packet Injection With WFP☆16Feb 20, 2023Updated 3 years ago
- library to load and parse Mach-O core files without dependencies☆17Oct 4, 2021Updated 4 years ago
- An advanced DKOM for drivers with "DRIVER_OBJECT"☆22Feb 19, 2023Updated 3 years ago
- Windows kernel driver that detects hypervisors by probing SIDT/LIDT edge cases, paging/TLB behaviors, privilege transitions, and timing e…☆37Mar 3, 2026Updated 2 weeks ago
- Rust program for interfacing with the gigabyte driver to gain access to powerful primitives such as arbitrary kernel memcpy.☆17Nov 26, 2022Updated 3 years ago
- An example code of CiGetCertPublisherName☆16Mar 24, 2022Updated 3 years ago
- Full reversing of the Microsoft Auxiliary Windows API Library and ported to C☆24Dec 17, 2024Updated last year
- A basic PE parser for 32-bit Windows executables.☆14May 24, 2017Updated 8 years ago
- A simple C++ driver base with KD data block☆11Jun 25, 2022Updated 3 years ago
- ☆17Aug 31, 2023Updated 2 years ago
- ☆41Mar 23, 2023Updated 2 years ago
- WinDbg installer/updater☆45Jul 11, 2023Updated 2 years ago
- ☆17Dec 18, 2020Updated 5 years ago
- Provides commands to read from and write to arbitrary kernel-mode memory for users with the Administrator privilege. HVCI compatible. No …☆23Jun 16, 2024Updated last year
- ☆27Oct 16, 2017Updated 8 years ago
- ASM Bootkit that patches DSE at boot allowing to load unsigned drivers☆16Aug 24, 2025Updated 6 months ago
- A simple way to spoof return addresses using an exception handler☆44Aug 3, 2022Updated 3 years ago
- A minimalistic way to spoof return addresses without using exceptions☆18Jul 26, 2022Updated 3 years ago
- Inter-binary control flow graphing☆38Feb 25, 2026Updated 3 weeks ago
- Released alongside with a talk at REcon 2023, TheRestarter is an interactive command-line tool is designed to interact with the Windows …☆15Jun 8, 2023Updated 2 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆73Aug 11, 2023Updated 2 years ago
- Using the peculiar behaviour of the VPGATHER instructions to determine if an address will fault before it is truly accessed. All done in …☆55Dec 30, 2025Updated 2 months ago
- An Automated Heap Feng Shui Tool☆18Jun 27, 2022Updated 3 years ago
- Abusing RtlAdjustPrivilege and NtSetInformationProcess to cause a BSOD from usermode☆20Sep 1, 2022Updated 3 years ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆104Jun 26, 2023Updated 2 years ago
- ☆46Jul 19, 2023Updated 2 years ago
- A Hobbyist Operating System based off the ReactOS/NT Kernel experimenting with OS Development.☆30Jul 29, 2012Updated 13 years ago
- stack based buffer overflow in MsIo64.sys, Proof of Concept Local Privilege Escalation to nt authority/system☆12Jun 7, 2021Updated 4 years ago
- ☆14Jun 21, 2020Updated 5 years ago
- x86 and x64 assembly "read-eval-print loop" for Windows☆35Aug 13, 2017Updated 8 years ago
- Memory manipulation library for Linux.☆28Jun 9, 2025Updated 9 months ago
- SurgeFuzz: Surge-Aware Directed Fuzzing for CPU Designs (ICCAD 2023)☆23Dec 5, 2024Updated last year
- A C++ syscall ID extractor for Windows. Developed, debugged and tested on 20H2.☆21May 25, 2021Updated 4 years ago
- reverse engineering of the windows nt kernel debugger protocol & reimplementation.☆36Jul 2, 2024Updated last year
- ☆24Mar 30, 2021Updated 4 years ago