insn (ultracage)

ultracage

Geek Repo

Company:@NationalSecurityAgency

Location:0xNemi

Github PK Tool:Github PK Tool

insn's repositories

pipedriver

Communicate from ring-0 to ring-3 using NamedPipes.

Language:CStargazers:7Issues:0Issues:0

ssdtmeme

Demonstrates SSDT hooking, technique often used by BattlEye. Only works in ring-0 privileges

Language:C++Stargazers:7Issues:0Issues:0

wardenrekter

Kill most of Overwatch 2's core anti-debugger components. (if not all :D)

Language:C++Stargazers:4Issues:0Issues:0

smart-uefi

communicate through EFI variables without an EFI driver

Language:C++Stargazers:2Issues:0Issues:0
Language:C++License:MITStargazers:2Issues:1Issues:0

OnlyCerts-POC

Whitelist certificates from ring3, cba add integrity checks to prevent program for being tampered with

Language:C++Stargazers:1Issues:0Issues:0

shmb

runtime shared memory ring0 example

Language:C++Stargazers:1Issues:0Issues:0

Awesome-Bootkits-Rootkits-Development

A curated compilation of extensive resources dedicated to bootkit and rootkit development.

License:GPL-3.0Stargazers:0Issues:0Issues:0

BlackLotus

BlackLotus UEFI Windows Bootkit

Stargazers:0Issues:0Issues:0

blairhv

x64 intel hypervisor with vmcs, vmx and physical page support

License:MITStargazers:0Issues:0Issues:0

EasyAntiCheat-Emulator

Simple DLL that spoofs EasyAntiCheat on most games

Stargazers:0Issues:0Issues:0

InterDKOM

Kernelmode driver with hijacked IOCTL payload, physical memory support and DTB bruteforce

Language:CStargazers:0Issues:0Issues:0

Memeory

Unlock paging table accesses on Windows.

Language:CLicense:MITStargazers:0Issues:0Issues:0

memflow

physical memory introspection framework

License:MITStargazers:0Issues:0Issues:0

umap

Temp repo to spoof btbd/umap edit date

Stargazers:0Issues:0Issues:0

vmread-rs

Rust bindings for vmread

License:MITStargazers:0Issues:0Issues:0

W10M_unedited-decomp

Pure Hex-rays Decompiler Psudocode of various Windows 10 Mobile binaries, No edit have been done to the output, you will need to piece together each function, class etc.Provided "as-is"

Stargazers:0Issues:0Issues:0