therealdreg / lldb_reversing
Dreg's setup for lldb reversing. The simplest and easiest possible, without scripting. lldb debugging setup.
☆14Updated last year
Alternatives and similar repositories for lldb_reversing:
Users that are interested in lldb_reversing are comparing it to the libraries listed below
- Finding Truth in the Shadows☆92Updated 2 years ago
- Report and exploit of CVE-2023-36427☆90Updated last year
- Report and exploit of CVE-2024-21305.☆34Updated last year
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆79Updated 6 months ago
- ☆71Updated 2 years ago
- ☆87Updated 11 months ago
- All LLVM binaries scrambled with SigBreaker and used to test against llvm-lit☆14Updated 3 weeks ago
- Windows KASLR bypass using prefetch side-channel☆92Updated last year
- ☆45Updated last month
- WinDbg extension written in Rust to dump the CPU / memory state of a running VM☆117Updated 6 months ago
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆100Updated last year
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 9 months ago
- Abusing exceptions for code execution.☆110Updated 2 years ago
- Generate a PDB file given the old PDB file and an address mapping☆47Updated last month
- bypassing intel txt's tboot integrity checks via coreboot shim☆66Updated last month
- ☆25Updated 6 months ago
- ☆110Updated 2 years ago
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆34Updated last year
- A few examples of how to trap virtual memory access on Windows.☆30Updated 4 months ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆62Updated 3 weeks ago
- A set of LLVM and GCC based plugins that perform code obfuscation.☆123Updated 2 months ago
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆152Updated last month
- Recon 2023 slides and code☆79Updated last year
- Minifilter Callback Patching Proof-of-Concept☆71Updated 2 years ago
- ☆42Updated 2 years ago
- Standalone Metasploit-like XOR encoder for shellcode☆48Updated 11 months ago
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆92Updated 6 months ago
- This repo contains EXPs about Vulnerable Windows Driver☆45Updated 11 months ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆51Updated this week
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year