Windows/Linux LSA credential extractor for lsass.dmp minidumps. Targets Windows 11 24H2/25H2/26H1 and Windows Server 2025. Pure Win32, no DbgHelp, no dependencies. Extracts MSV, WDigest, Kerberos, CredMan, DPAPI. AES-CFB128 and 3DES-CBC decryption via BCrypt
☆36May 14, 2026Updated 3 months ago
Alternatives and similar repositories for KvcForensic
Users that are interested in KvcForensic are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Advanced DSE bypass tool for Windows 11 Build 26200+. Features symbol-less kernel resolution via dynamic pattern scanning, KDP bypass via…☆21Jun 29, 2026Updated 2 months ago
- KVC enables unsigned driver loading via DSE bypass (g_CiOptions patch, skci.dll hijack, SeCiCallbacks redirection) and PP/PPL manipulatio…☆315May 28, 2026Updated 3 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 5 months ago
- This is my starred repositories including the description for each tool. Makes search/filter over them easier.☆72Feb 26, 2025Updated last year
- Advanced AV/EDR Killer: Specialized Antivirus & Windows Defender killer for security professionals. Utilizes kernel-level IOCTLs for proc…☆26Apr 20, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Command-line utility to completely halt, disable, and neutralize Windows Defender and Tamper Protection. Bypasses forced UAC and GUI requ…☆59Jul 17, 2026Updated last month
- Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR…☆110Aug 8, 2026Updated 3 weeks ago
- An implementation of PyADRecon using ADWS instead of LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD d…☆55Jul 10, 2026Updated last month
- 🌳 Automated triage scanner for Windows kernel driver vulnerabilities. Ghidra headless + heuristic scoring.☆17Aug 6, 2026Updated 3 weeks ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆201Jun 6, 2026Updated 2 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 4 months ago
- Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).☆121Jun 22, 2026Updated 2 months ago
- Exploit LnvMSRIO.sys vulnerable driver☆18Dec 10, 2025Updated 8 months ago
- Windows Shell Link (LNK) Proof of Concept☆16Jul 19, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Decrypt and Patch strings obfuscated with Appfuscator. Tested on Gremlin Stealer.☆16Nov 10, 2025Updated 9 months ago
- ☆17Jul 23, 2024Updated 2 years ago
- ☆29Feb 16, 2022Updated 4 years ago
- A sleepmask based on Ekko that preserves unwind data at sleep time.☆56Mar 30, 2026Updated 4 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆199Apr 27, 2026Updated 4 months ago
- Patching the Secure Kernel to enable debugging of VTL 1 Isolated User Mode☆73May 14, 2026Updated 3 months ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆109Jul 26, 2026Updated last month
- goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current…☆66Jun 28, 2026Updated 2 months ago
- The world's smallest TrustedInstaller launcher ~30KB of pure x64/x86/arm64 assembly. Hybrid CLI/GUI in one binary. Full NT privilege elev…☆54Aug 3, 2026Updated 3 weeks ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Linker for Beacon Object Files☆191Aug 14, 2026Updated 2 weeks ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆290Jun 22, 2026Updated 2 months ago
- Overview of MS Defender☆156Feb 20, 2026Updated 6 months ago
- usermode thread hijacking detection via working set page fault monitoring☆39Jul 17, 2026Updated last month
- BYOVD tool for manipulating Windows Protected Process Light (PPL) protection at the kernel level.☆95May 25, 2026Updated 3 months ago
- ExchangeHound is a defensive BloodHound OpenGraph collector for on-prem Microsoft Exchange that maps mailbox delegation and Exchange priv…☆77Apr 17, 2026Updated 4 months ago
- Collection of interesting Yara Rules☆18Aug 19, 2026Updated last week
- A set of tools and resources for analysis of Havoc C2☆30Feb 27, 2024Updated 2 years ago
- Lateral movement with DCOM DLL hijacking☆183Jul 4, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Windows kernel driver exploitation knowledge base — 28 case studies organized by driver type, grounded in real CVEs with build numbers an…☆42Mar 26, 2026Updated 5 months ago
- ☆63Feb 12, 2026Updated 6 months ago
- ☆57Apr 17, 2026Updated 4 months ago
- SystemGap - Maintenance Tools after privilege escalation☆60Jan 4, 2026Updated 7 months ago
- A small experiment on assigning a processes threads a specific CPU and then blocking it with a high priority thread☆33Sep 24, 2025Updated 11 months ago
- Azure Blob Storage C2 Profile for Mythic☆30Jan 30, 2026Updated 6 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 8 months ago