tandasat / kraft_dinner
Tool to dump UEFI runtime drivers implementing runtime services for Windows
☆95Updated 4 years ago
Alternatives and similar repositories for kraft_dinner:
Users that are interested in kraft_dinner are comparing it to the libraries listed below
- A native hypervisor designed for the Windows operating system☆120Updated 3 years ago
- Header only wrapper around Hex-Rays API in C++20.☆154Updated 3 weeks ago
- A simple x86_64 AMD-v hypervisor type-2 Programmed with C++, with soon to be added syscall hooks. [W.I.P]☆93Updated last year
- HelloAmdHvPkg is a type-1 research hypervisor for AMD processors.☆86Updated 4 years ago
- Intercepting DeviceControl via WPP☆131Updated 5 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆174Updated last year
- Resolve DOS MZ executable symbols at runtime☆93Updated 3 years ago
- ☆93Updated 7 years ago
- C++ library for parsing and manipulating PE files statically and dynamically.☆87Updated last year
- Ghetto user mode emulation of Windows kernel drivers.☆132Updated 2 months ago
- VM devirtualization PoC based on AsmJit and llvm☆107Updated 3 years ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆212Updated 5 years ago
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆71Updated last year
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆55Updated 11 months ago
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆77Updated 2 years ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆67Updated 2 years ago
- Header-only VMWare Backdoor API Implementation & Effortless VMX Patcher for Custom Guest-to-Host RPCs☆99Updated 4 years ago
- a minimalistic windows hypervisor for amd processors☆98Updated 2 years ago
- ☆67Updated 4 years ago
- Disks for DMA☆100Updated 3 years ago
- A driver that hooks C: volume using symbolic link callback to track all FS access to the volume☆103Updated 4 years ago
- Browse Page Tables on Windows (Page Table Viewer)☆194Updated 2 years ago
- Hooking SSDT with Avast Internet Security Hypervisor☆112Updated 5 years ago
- VT-based PCI device monitor (SPI)☆150Updated 4 years ago
- Translates WinDbg "dt" structure dump to a C structure☆127Updated 8 years ago
- alternative smm driver for ryzen motherboards☆112Updated 3 months ago
- Lifting from native architecture to VTIL. (WIP)☆74Updated 2 years ago
- A ProcMon-esque tool for monitoring Windows Kernel Drivers☆54Updated 3 years ago
- A portable header only library extending the C++20 STL.☆72Updated 9 months ago
- Windows PDB parser for kernel-mode environment.☆93Updated 2 years ago