Windy Bug's starred repositories

unicorn

Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)

Language:CLicense:GPL-2.0Stargazers:7536Issues:213Issues:1068

Windows-driver-samples

This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples.

pocs

Proof of Concepts (PE, PDF...)

RpcView

RpcView is a free tool to explore and decompile Microsoft RPC interfaces

Language:C++License:GPL-3.0Stargazers:918Issues:50Issues:39

WDExtract

Extract Windows Defender database from vdm files and unpack it

Language:CLicense:BSD-2-ClauseStargazers:423Issues:14Issues:4

SinMapper

usermode driver mapper that forcefully loads any signed kernel driver (legit cert) with a big enough section (example: .data, .rdata) to map your driver over. the main focus of this project is to prevent modern anti-cheats (BattlEye, EAC) from finding your driver and having the power to hook anything due to being inside of legit memory (signed legit driver).

RPCMon

RPC Monitor tool based on Event Tracing for Windows

Language:C#License:Apache-2.0Stargazers:326Issues:12Issues:2

warbird-hook

Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard

Language:C++License:GPL-3.0Stargazers:234Issues:4Issues:0

winio

A fork of WinIo which developed by Yariv Kaplan from http://www.internals.com

Language:CLicense:NOASSERTIONStargazers:183Issues:20Issues:1

GhostMapperUM

manual map unsigned driver over signed memory

ntdoc

Native API online documentation, based on the System Informer (formerly Process Hacker) phnt headers

Language:PythonLicense:NOASSERTIONStargazers:144Issues:5Issues:0

classinformer-ida8

IDA Class Informer plugin for IDA 8.x

CiDllDemo

Use ci.dll API for validating Authenticode signature of files

Language:C++License:MITStargazers:126Issues:6Issues:4

Suspending-Techniques

Comparing, discussing, and bypassing various techniques for suspending and freezing processes on Windows.

Language:PascalStargazers:111Issues:8Issues:0

24h2-nt-exploit

Exploit targeting NT kernel in 24H2 Windows Insider Preview

Language:CLicense:MITStargazers:101Issues:5Issues:0

windows-software-policy

Research on obfuscated licensing APIs / CLIP service in the Windows kernel

KernelInjector

PoC kernel to usermode injection

RansomGuard

anti-ransomware file-system filter

Language:C++License:MITStargazers:37Issues:2Issues:0

DataptrHooks

ntoskrnl .data hooks for UM-KM communication

vmware-svga

not mine, clone from

Language:CStargazers:33Issues:2Issues:0

WinMain-is-usually-a-function

Windows NT port of 'Main is usually a function. So then when is it not?'

Language:C++License:GPL-3.0Stargazers:24Issues:4Issues:0

WFPCalloutReserach

research revolving the windows filtering platform callout mechanism

Language:C++Stargazers:21Issues:2Issues:0

KeystrokeSniffer

a windows kernel keylogger that works

Language:C++License:MITStargazers:18Issues:3Issues:0

InstrumentationCallbacks

A native Windows library for intercepting kernel-to-user transitions using instrumentation callbacks

Language:C++License:GPL-3.0Stargazers:14Issues:2Issues:0

PnpNotifyResearch

a driver to enumerate registered pnp callbacks for a particular interface class based on reversal of IoRegisterPlugPlayNotification

Language:CStargazers:7Issues:1Issues:0
Language:CMakeLicense:MITStargazers:3Issues:5Issues:0
Language:C++Stargazers:3Issues:0Issues:0