x0reaxeax / rwlazer64
Win64 UEFI Driver-based tool for unrestricted memory R/W
☆26Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for rwlazer64
- Allows you to find the use of ScyllaHide, if your program will debug and restore hooking functions bytes.☆24Updated 5 years ago
- Another UEFI runtime bootkit☆30Updated last year
- just proof of concept. hooking MmCopyMemory PG safe.☆63Updated last year
- Compileable POC of namazso's x64 return address spoofer.☆47Updated 4 years ago
- Me fockin' pe protector☆45Updated 2 years ago
- ntoskrnl .data hooks for UM-KM communication☆34Updated 5 months ago
- POC Hook of nt!HvcallCodeVa☆50Updated last year
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆106Updated last year
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆24Updated last month
- Windows PDB parser for kernel-mode environment.☆90Updated last year
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆46Updated last year
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆41Updated last year
- clearing traces of a loaded driver☆44Updated 2 years ago
- DSE & PG bypass via BYOVD attack☆37Updated 7 months ago
- The sequel to Voyager☆18Updated 3 months ago
- x64 Windows implementation of virtual-address to physical-address translation☆41Updated 3 years ago
- ☆49Updated 2 years ago
- PoC kernel to usermode injection☆60Updated 8 months ago
- Experiment with PAGE_GUARD protection to hide memory from other processes☆39Updated 5 months ago
- TS-Changer - Forces the machine in/out of TestSigning Mode at runtime.☆64Updated last year
- Windows kernel driver template for cmkr (with testsigning).☆30Updated last year
- Virtual and physical memory hacking library using gigabyte vulnerable driver☆70Updated last year
- Tool to dump EFI runtime drivers.☆34Updated 9 months ago
- Bypassing kernel patch protection runtime☆19Updated last year
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆39Updated 5 months ago
- ☆38Updated last year