therealdreg / masm32-kernel-programming
masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)
☆123Updated last year
Alternatives and similar repositories for masm32-kernel-programming:
Users that are interested in masm32-kernel-programming are comparing it to the libraries listed below
- Recon 2023 slides and code☆79Updated last year
- Single header version of System Informer's phnt library.☆213Updated this week
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆143Updated 2 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 9 months ago
- Advanced driver monitoring utility.☆208Updated 2 years ago
- ☆114Updated this week
- Small tool to convert beteween the PE alignments (raw and virtual).☆87Updated 2 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆245Updated 2 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆114Updated 2 years ago
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆152Updated last month
- Reverse engineering winapi function loadlibrary.☆189Updated 2 years ago
- Admin to Kernel code execution using the KSecDD driver☆246Updated last year
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆136Updated 8 months ago
- Writeups for CTF challenges☆31Updated last year
- PoC Anti-Rootkit/Anti-Cheat Driver.☆190Updated last week
- MalUnpack companion driver☆98Updated 10 months ago
- ☆126Updated 3 weeks ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆227Updated 2 years ago
- Debugger Anti-Detection Benchmark☆332Updated last year
- Static Binary Instrumentation tool for Windows x64 executables☆201Updated this week
- x86/x64 Ring 0/-2 System Freezer/Debugger☆115Updated 5 months ago
- A dynamic unpacking tool☆134Updated last year
- Dreg's setup for lldb reversing. The simplest and easiest possible, without scripting. lldb debugging setup.☆14Updated last year
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆285Updated last year
- Process Injection using Thread Name☆259Updated 2 weeks ago
- uefi diskless persistence technique + OVMF secureboot bypass☆61Updated last year
- My notes while studying Windows exploitation☆188Updated last year
- Hooking Windows' exception dispatcher to protect process's PML4☆167Updated 3 months ago
- ☆87Updated 11 months ago