xsh3llsh0ck / Calamity
Example of using Windows Platform Binary Table (WPBT)
☆15Updated last year
Alternatives and similar repositories for Calamity:
Users that are interested in Calamity are comparing it to the libraries listed below
- Another UEFI runtime bootkit☆28Updated last year
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆77Updated 2 years ago
- Me fockin' pe protector☆45Updated 2 years ago
- Win64 UEFI Driver-based tool for unrestricted memory R/W☆27Updated 2 years ago
- Binary rewriter for 64-bit PE files.☆67Updated 11 months ago
- Windows kernel driver template for cmkr (with testsigning).☆30Updated last year
- Windows PDB parser for kernel-mode environment.☆93Updated 2 years ago
- EFI bootkit for loading unsigned drivers☆15Updated 6 months ago
- Tool to dump EFI runtime drivers.☆35Updated 10 months ago
- kernel driver used to monitor the activity of BadlionAnticheat.sys by patching its IAT☆32Updated 3 years ago
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆39Updated 7 months ago
- Simple and lightweight hypervisor for AMD processors☆27Updated last month
- intel vt-x type 2 hypervisor☆48Updated 6 months ago
- devirtualization vmprotect☆61Updated last year
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆55Updated 11 months ago
- Small driver that uses alternative syscalls feature (the project is still under development).☆15Updated 8 months ago
- PAGE_GUARD based hooking library☆42Updated 2 years ago
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆78Updated 3 months ago
- just proof of concept. hooking MmCopyMemory PG safe.☆65Updated last year
- x86-64 user mode emulation using Zydis☆41Updated last week
- vdk is a set of utilities used to help with exploitation of a vulnerable driver.☆39Updated 2 years ago
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆71Updated last year
- x64 PE-COFF virtualization driven obfuscation engine☆53Updated 2 years ago
- 这篇文章的目的是介绍一款实验性项目基于COM命名管道或者Windows Hyper-V虚拟机Vmbus通道实现的运行在uefi上的windbg调试引擎开发心得☆40Updated 7 months ago
- Header-only C++ library for producing PE files.☆29Updated last year
- ☆26Updated last year
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆45Updated last year
- advanced C/C++ antidebugging library for Windows☆14Updated this week