Windows/Linux LSA credential extractor for lsass.dmp minidumps. Targets Windows 11 24H2/25H2/26H1 and Windows Server 2025. Pure Win32, no DbgHelp, no dependencies. Extracts MSV, WDigest, Kerberos, CredMan, DPAPI. AES-CFB128 and 3DES-CBC decryption via BCrypt
☆35May 14, 2026Updated 2 months ago
Alternatives and similar repositories for KvcForensic
Users that are interested in KvcForensic are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Advanced DSE bypass tool for Windows 11 Build 26200+. Features symbol-less kernel resolution via dynamic pattern scanning, KDP bypass via…☆22Jun 29, 2026Updated last month
- KVC enables unsigned driver loading via DSE bypass (g_CiOptions patch, skci.dll hijack, SeCiCallbacks redirection) and PP/PPL manipulatio…☆303May 28, 2026Updated 2 months ago
- PPLReaper is a Windows UNSIGNED kernel driver + userland companion tool designed to inspect and manipulate Protected Process Light (PPL) …☆24Mar 4, 2026Updated 5 months ago
- This is my starred repositories including the description for each tool. Makes search/filter over them easier.☆71Feb 26, 2025Updated last year
- Advanced AV/EDR Killer: Specialized Antivirus & Windows Defender killer for security professionals. Utilizes kernel-level IOCTLs for proc…☆25Apr 20, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Command-line utility to completely halt, disable, and neutralize Windows Defender and Tamper Protection. Bypasses forced UAC and GUI requ…☆51Jul 17, 2026Updated 2 weeks ago
- Phantom-Evasion-Loader is a standalone, pure x64 Assembly injection engine engineered to minimize the detection surface of modern EDR/XDR…☆110Jul 20, 2026Updated 2 weeks ago
- An implementation of PyADRecon using ADWS instead of LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD d…☆55Jul 10, 2026Updated 3 weeks ago
- 🌳 Automated triage scanner for Windows kernel driver vulnerabilities. Ghidra headless + heuristic scoring.☆16Jul 1, 2026Updated last month
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated 2 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 3 months ago
- Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).☆118Jun 22, 2026Updated last month
- Exploit LnvMSRIO.sys vulnerable driver☆18Dec 10, 2025Updated 7 months ago
- Windows Shell Link (LNK) Proof of Concept☆16Jul 19, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆17Jul 23, 2024Updated 2 years ago
- Decrypt and Patch strings obfuscated with Appfuscator. Tested on Gremlin Stealer.☆15Nov 10, 2025Updated 8 months ago
- ☆29Feb 16, 2022Updated 4 years ago
- A sleepmask based on Ekko that preserves unwind data at sleep time.☆56Mar 30, 2026Updated 4 months ago
- Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods…☆197Apr 27, 2026Updated 3 months ago
- Patching the Secure Kernel to enable debugging of VTL 1 Isolated User Mode☆74May 14, 2026Updated 2 months ago
- A stealthy and modular Windows loader designed to bypass modern EDR solutions using Module Stomping, Stack Duplication, and Advanced Slee…☆78Jul 26, 2026Updated last week
- goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current…☆66Jun 28, 2026Updated last month
- The world's smallest TrustedInstaller launcher ~30KB of pure x64/x86/arm64 assembly. Hybrid CLI/GUI in one binary. Full NT privilege elev…☆55Updated this week
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Linker for Beacon Object Files☆191Jul 28, 2026Updated last week
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆280Jun 22, 2026Updated last month
- Overview of MS Defender☆155Feb 20, 2026Updated 5 months ago
- usermode thread hijacking detection via working set page fault monitoring☆40Jul 17, 2026Updated 2 weeks ago
- BYOVD tool for manipulating Windows Protected Process Light (PPL) protection at the kernel level.☆90May 25, 2026Updated 2 months ago
- wmiexec2.0 is the same wmiexec that everyone knows and loves (debatable). This 2.0 version is obfuscated to avoid well known signatures …☆68Apr 2, 2026Updated 4 months ago
- ExchangeHound is a defensive BloodHound OpenGraph collector for on-prem Microsoft Exchange that maps mailbox delegation and Exchange priv…☆76Apr 17, 2026Updated 3 months ago
- Collection of interesting Yara Rules☆16Jul 26, 2026Updated last week
- A set of tools and resources for analysis of Havoc C2☆30Feb 27, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Lateral movement with DCOM DLL hijacking☆182Jul 4, 2025Updated last year
- Windows kernel driver exploitation knowledge base — 28 case studies organized by driver type, grounded in real CVEs with build numbers an…☆20Mar 26, 2026Updated 4 months ago
- ☆62Feb 12, 2026Updated 5 months ago
- ☆53Apr 17, 2026Updated 3 months ago
- Azure Blob Storage C2 Profile for Mythic☆30Jan 30, 2026Updated 6 months ago
- A small experiment on assigning a processes threads a specific CPU and then blocking it with a high priority thread☆33Sep 24, 2025Updated 10 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 7 months ago