103 results for “topic:windows-kernel”
Windows File System Proxy - FUSE for Windows
State-of-the-art native debugging tools
Adversary tradecraft detection, protection, and hunting
Intel VT-x based hypervisor aiming to provide a thin VM-exit filtering platform on Windows.
SoftICE-like kernel debugger for Windows 11
Kernel mode WinDbg extension and PoCs for token privilege investigation.
The first Computer Emergency Response (ARK) Tools for young people ;) 年轻人的第一款应急响应(ARK)工具 ;)
Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.
A minimalistic educational hypervisor for Windows on AMD processors.
SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.
kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x
Windows Storage Proxy Driver - User mode disk storage
C++ STL in the Windows Kernel with C++ Exception Support
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks
The Universal C++ RunTime library, supporting kernel-mode C++ exception-handler and STL.
Tools and PoCs for Windows syscall investigation.
Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with VMware and Hyper-V.
msFuzz is a coverage-guided fuzzer for Windows kernel drivers that utilizes Intel PT and leverages constraint and dependency analysis to guide fuzzing.
C/C++ Runtime library for system file (Windows Kernel Driver) - Supports Microsoft STL
C# Utilities for Windows Notification Facility
Research on obfuscated licensing APIs / CLIP service in the Windows kernel
Enumerate user mode shared memory mappings on Windows.
masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)
A native hypervisor designed for the Windows operating system
IoCreateDriver Implementation, it can be useful if you're trying to bypass anticheats
NTFUZZ: Enabling Type-Aware Kernel Fuzzing on Windows with Static Binary Analysis (IEEE S&P '21)
🔍 Code to read / write the Process Memory from the Kernel 🔧
Android Memory Tools written in python for RAM data reading and writing process of android, linux and windows os's.
Example Windows Kernel-mode Driver which enumerates running processes.
Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reachability tracing, and scoring