Some of my windows kernel exploits for learning purposes
☆138May 18, 2022Updated 4 years ago
Alternatives and similar repositories for windows-kernel-exploits
Users that are interested in windows-kernel-exploits are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆149Jun 5, 2023Updated 3 years ago
- PoC exploiting Aligned Chunk Confusion on Windows kernel Segment Heap☆213Jul 2, 2020Updated 6 years ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆259Jul 5, 2022Updated 4 years ago
- ☆165Jul 31, 2022Updated 4 years ago
- ☆113May 24, 2022Updated 4 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CV…☆264Sep 1, 2022Updated 3 years ago
- Sleep Obfuscation☆844Dec 3, 2023Updated 2 years ago
- ☆26Sep 29, 2022Updated 3 years ago
- Kernel Exploits☆256Jul 18, 2021Updated 5 years ago
- A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and re…☆32Aug 23, 2023Updated 3 years ago
- OSED Practice binary☆27Nov 23, 2023Updated 2 years ago
- HEVD Exploit: BufferOverflowNonPagedPoolNx on Windows 10 22H2 - Escalating from Low Integrity to SYSTEM via Aligned Chunk Confusion☆66Apr 22, 2025Updated last year
- Writeup of Payload Techniques in C involving Mutants, Session 1 -> Session 0 migration, and Self-Deletion of payloads.☆128Apr 24, 2022Updated 4 years ago
- Performing Indirect Clean Syscalls☆625May 2, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- PoCs and tools for investigation of Windows process execution techniques☆958Feb 2, 2026Updated 6 months ago
- Some drivers I've written while solving exercises from Practical Reverse Engineering☆15Jan 9, 2022Updated 4 years ago
- Kernel mode WinDbg extension and PoCs for token privilege investigation.☆970Aug 20, 2026Updated last week
- Implementation of several code injection techniques.☆25Mar 12, 2022Updated 4 years ago
- HackSysExtremeVulnerableDriver exploits for latest Windows 10 version☆25Jan 13, 2026Updated 7 months ago
- A variation CredBandit that uses compression to reduce the size of the data that must be trasnmitted.☆19Jun 24, 2021Updated 5 years ago
- Progress of learning kernel development☆14Nov 20, 2022Updated 3 years ago
- Tools and PoCs for Windows syscall investigation.☆365Dec 2, 2025Updated 8 months ago
- 横向移动三剑客 ( Lateral movement tools)☆30Nov 16, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Function hooks in Windows NT Kernel☆27Oct 13, 2020Updated 5 years ago
- ☆118Aug 7, 2022Updated 4 years ago
- A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC☆376May 24, 2022Updated 4 years ago
- ☆1,844Aug 30, 2024Updated 2 years ago
- Leaked Windows processes handles identification tool☆299Mar 14, 2022Updated 4 years ago
- A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)☆596Apr 8, 2025Updated last year
- A PoC for adding NtContinue to CFG allowed list in order to make Ekko work in a CFG protected process☆116Aug 29, 2022Updated 4 years ago
- Zenith exploits a memory corruption vulnerability in the NetUSB driver to get remote-code execution on the TP-Link Archer C7 V5 router fo…☆131Apr 25, 2022Updated 4 years ago
- ☆357May 16, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Some stuff for PHD2021☆14May 21, 2025Updated last year
- A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in c…☆122Jul 21, 2022Updated 4 years ago
- Dumping LSASS with a duplicated handle from custom LSA plugin☆207Feb 23, 2022Updated 4 years ago
- ☆93Oct 17, 2020Updated 5 years ago
- Notes, exploits, and other stuff that I create while learning Linux Kernel exploitation techniques☆97Mar 21, 2023Updated 3 years ago
- A red teaming attack paradigm against AI Agents☆34Mar 9, 2025Updated last year
- ☆88Jan 12, 2022Updated 4 years ago