Windy Bug's repositories

GhostMapperUM

manual map unsigned driver over signed memory

KDP-compatible-driver-loader

KDP compatible unsigned driver loader leveraging a write primitive in one of the IOCTLs of gdrv.sys

Language:CStargazers:101Issues:0Issues:0

KernelInjector

PoC kernel to usermode injection

MinifilterHook

silence file system monitoring components by hooking their minifilters

Language:CLicense:MITStargazers:41Issues:2Issues:1

DataptrHooks

ntoskrnl .data hooks for UM-KM communication

WFPCalloutReserach

research revolving the windows filtering platform callout mechanism

Language:C++Stargazers:19Issues:0Issues:0

KeystrokeSniffer

a windows kernel keylogger that works

Language:C++License:MITStargazers:17Issues:3Issues:0

FileHide

filter driver to hide files and directories

Language:C++License:MITStargazers:10Issues:2Issues:1

PnpNotifyResearch

a driver to enumerate registered pnp callbacks for a particular interface class based on reversal of IoRegisterPlugPlayNotification

Language:CStargazers:7Issues:1Issues:0

BackupFilter

backup your documents

Language:C++License:MITStargazers:3Issues:0Issues:0

egghunters

Windows SEH based egghunter

Language:PythonStargazers:3Issues:2Issues:0

EventPic

messing around with pic and events

Language:C++Stargazers:3Issues:2Issues:0

shellcodes

Windows Shellcodes

Language:PythonStargazers:3Issues:2Issues:0

AsyncIo

asynchronous ioctl completion sample

Language:C++Stargazers:2Issues:1Issues:0
Language:C++Stargazers:1Issues:1Issues:0
Language:JavaScriptLicense:MITStargazers:0Issues:0Issues:0