xrv3ovl's repositories

ida_kern_til

Tools for building TIL for IDA SDK & exporting them to python wrapper

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

Windows-Internals-Build-10.0.-18362-

Another Windows Internals repo

Stargazers:0Issues:0Issues:0

OfficeActivator

Office Activator

Stargazers:0Issues:0Issues:0

Banshee

Experimental Windows x64 Kernel Rootkit.

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

BYOVDKit

bring your own vulnerable driver

Stargazers:0Issues:0Issues:0

EtwTi-FluctuationMonitor

Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections

Stargazers:0Issues:0Issues:0

HyperDeceit

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system tasks with ease.

License:MITStargazers:0Issues:0Issues:0

DLLSpy

DLL Hijacking Detection Tool

License:LGPL-3.0Stargazers:0Issues:0Issues:0

Cool-Hypervisor

A intel hypervisor, implementing many virtualization techniques

License:MITStargazers:0Issues:0Issues:0

WID_LoadLibrary

Reverse engineering winapi function loadlibrary.

License:MITStargazers:0Issues:0Issues:0

IDTHook-x86

Detour hooking IRQ1 ISR through IDT (Interrupt Descriptor Table)

Stargazers:0Issues:0Issues:0

CompatLib

Compatibility library for re-establishing Windows XP SP-3 support in VS2019

License:CC0-1.0Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

idatil2c

Convert IDA Type Library `*.til` to Compilable C Header!

Stargazers:0Issues:0Issues:0

bootlicker

A generic UEFI bootkit used to achieve initial usermode execution. It works with modifications.

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

system_trace_tool

内核驱动加载/卸载痕迹清理,努力绕过反作弊吧 PiDDBCacheTable and MmLastUnloadedDriver

License:Apache-2.0Stargazers:0Issues:0Issues:0

InfinityHookPro

InfinityHookPro Win7 -> Win11 latest

License:MITStargazers:0Issues:0Issues:0

Privileger

Privileger is a tool to work with Windows Privileges

Stargazers:0Issues:0Issues:0

Proxy-Function-Calls-For-ETwTI

The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/

License:GPL-3.0Stargazers:0Issues:0Issues:0

fileid

File Type Identification Tool & Metadata extractor intended for automation

License:MITStargazers:0Issues:0Issues:0

PINKPANTHER

Windows x64 handcrafted token stealing kernel-mode shellcode

License:GPL-3.0Stargazers:0Issues:0Issues:0

windows-ps-callbacks-experiments

Files for http://blog.deniable.org/posts/windows-callbacks/

Stargazers:0Issues:0Issues:0

HyperWin

A native hypervisor designed for the Windows operating system

Language:CLicense:GPL-3.0Stargazers:0Issues:0Issues:0

DynamicWrapperEx

x64 Registration-Free In-Process COM Automation Server.

License:GPL-3.0Stargazers:0Issues:0Issues:0

win32-ex

Win32 API Experimental(or Extension) features

License:MITStargazers:0Issues:0Issues:0

CInject

Windows Kernel inject (no module no thread)

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0