k's repositories

ReverseKit

x64 Dynamic Reverse Engineering Toolkit

Language:C++License:MITStargazers:561Issues:14Issues:3

mhydeath

Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.

NVDrv

Abusing nvidia driver (nvoclock.sys) for physical/virtual memory and control register manipulation.

GDRVLoader

Unsigned driver loader using CVE-2018-19320

ZeroThreadKernel

Recursive and arbitrary code execution at kernel-level without a system thread creation

Language:C++Stargazers:147Issues:6Issues:0

Reversing-a-signed-driver

Reverse Engineering a signed kernel driver packed and virtualized with VMProtect 3.6

Demystifying-PatchGuard

Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unauthorized modifications to the Windows kernel. The analysis is done through practical engineering, with a focus on understanding PatchGuard's inner workings.

GDRVLib

Virtual and physical memory hacking library using gigabyte vulnerable driver

IDTHook-x86

Detour hooking IRQ1 ISR through IDT (Interrupt Descriptor Table)

Language:C++Stargazers:16Issues:2Issues:0

CritBSOD

Abusing RtlAdjustPrivilege and NtSetInformationProcess to cause a BSOD from usermode

Language:C++Stargazers:14Issues:3Issues:0
Language:PythonStargazers:7Issues:1Issues:0

ia32-doc

IA32-doc is a project which aims to put as many definitions from the Intel Manual into machine-processable format as possible

Language:CLicense:MITStargazers:1Issues:0Issues:0

WRK

The Windows Research Kernel (WRK)

Language:CStargazers:1Issues:0Issues:0