xsh3llsh0ck / Deadwing
SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.
☆85Updated 6 months ago
Alternatives and similar repositories for Deadwing:
Users that are interested in Deadwing are comparing it to the libraries listed below
- Tool to dump EFI runtime drivers.☆35Updated last year
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆120Updated 2 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆184Updated last year
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆59Updated last year
- Unknowncheats Magically Optimized Tidy Mapper using nvaudio☆121Updated 10 months ago
- manual map unsigned driver over signed memory☆186Updated last year
- Kernel Level NMI Callback Blocker☆84Updated 8 months ago
- ntoskrnl .data hooks for UM-KM communication☆41Updated 11 months ago
- Detects virtual machines and malware analysis environments☆127Updated 2 years ago
- Hooking Windows' exception dispatcher to protect process's PML4☆167Updated 3 months ago
- Using Windows' own bootloader as a shim to bypass Secure Boot☆169Updated 9 months ago
- DSE & PG bypass via BYOVD attack☆50Updated last year
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆143Updated 3 years ago
- nmi stackwalking + module verification☆114Updated last year
- Binary rewriter for 64-bit PE files.☆71Updated last year
- Crashes ida on static analyses.☆106Updated last week
- My EAC & BE Rady CR3 Reading & Writing source that I use for my KM Drivers.☆62Updated 8 months ago
- ☆185Updated this week
- Shows an example of how to implement VT-d/AMD-Vi on Windows☆108Updated last year
- Windows PDB parser for kernel-mode environment.☆95Updated 2 years ago
- 🪝 Different aproaches to detecting EPT hooks☆107Updated 3 years ago
- Experiment with PAGE_GUARD protection to hide memory from other processes☆44Updated 10 months ago
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆198Updated 6 months ago
- A library to assist with memory & code protection.☆56Updated last year
- Kernel ReClassEx☆61Updated last year
- PoC Anti-Rootkit/Anti-Cheat Driver.☆190Updated last week
- An x86-64 code virtualizer for VM based obfuscation☆119Updated 4 months ago
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆114Updated last year
- ☆74Updated last year
- Collection of hypervisor detections☆236Updated 7 months ago