6-day current streak·44-day longest streak
-
windbg-decompile-ext ★ PINNED
WinDbg x64 extension that disassembles live functions and uses an LLM to produce verified pseudocode.
C++ ★ 110 1mo agoExplain → -
kn-live-dbg ★ PINNED
Windows kernel research tool. Looks like a debugger, but it is not a debugger. It uses a kernel driver to provide a WinDbg-like live kernel debugging experience from a TUI console.
C++ ★ 70 5h agoExplain → -
kernullist-blog ★ PINNED
kernullist-blog
Ruby ★ 0 22d agoExplain → -
PseudoForge ★ PINNED
An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts
Python ★ 158 18d agoExplain → -
ETWPrism ★ PINNED
User-mode ETW interception and telemetry manipulation lab for Windows security research.
Rust ★ 42 1mo agoExplain → -
KnWin32ApiMonitor ★ PINNED
Modern Win32 API monitor for Windows security, reverse engineering, debugging, and anti-cheat research.
C++ ★ 43 27d agoExplain → -
kernforge
Kernforge is a project intelligence and fuzzing workbench for Windows security, anti-cheat engineering, and evidence-backed verification.
Go ★ 25 1d agoExplain → -
PyProcFilter
Process Filter for Python
C ★ 16 10y agoExplain → -
kn-diff-pool
Windows kernel Big Pool snapshot/diff tool with a kernel-mode driver and a Go TUI.
Go ★ 13 2mo agoExplain → -
krn_pcre
Windows Kernel Mode PCRE
C ★ 10 11y agoExplain → -
CodersRoundTable
Gamified code review: four legendary tech personas debate your source code with real-time speech bubbles, neon line highlighting, and 16-bit RPG visuals.
Python ★ 7 1mo agoExplain → -
Rubbish
Rubbish Collection
Batchfile ★ 6 10y agoExplain → -
glow-audio
A neon audio utility that controls real Windows playback devices directly, auto-switches on game launch
Rust ★ 4 14d agoExplain → -
knFileCatcher
A Windows minifilter-backed file capture tool. Tracks processes that run under user-specified watch roots and their descendants.
C++ ★ 4 1mo agoExplain → -
ariago
ARIA implementation with Go
Go ★ 4 10y agoExplain → -
CogniFind
100% offline, on-device local semantic document search for Windows (Tauri + Python, sqlite-vec). Spotlight-style popup, hybrid search, OCR, system tray.
Python ★ 3 22d agoExplain → -
YourOpenRoom ⑂
A browser-based desktop where AI Agent operates every app through natural language.
TypeScript ★ 1 2d agoExplain → -
written-by-me
Your writing style, distilled into a Skill.md for AI agents.
JavaScript ★ 1 2mo agoExplain → -
ruleward
Guard your AI agent rules — lints AGENTS.md, CLAUDE.md & Cursor rules for conflicts, duplication, bloat, and drift from real code.
TypeScript ★ 1 1mo agoExplain → -
IDAssist ⑂
AI-Powered Reverse Engineering Plugin for IDA Pro
★ 1 4mo agoExplain → -
phnt ⑂
Native API header files for the Process Hacker project.
★ 1 6y agoExplain → -
story-box
No description.
HTML ★ 0 3d agoExplain → -
your-master ⑂
💖🧸 Self hosted, you-owned Grok Companion, a container of souls of waifu, cyber livings to bring them into our worlds, wishing to achieve Neuro-sama's altitude. Capable of realtime voice chat, Minecraft, Factorio playing. Web / macOS / Windows supported.
TypeScript ★ 0 9d agoExplain → -
OhMyDisplay
Windows tray utility that solves two chronic display/power annoyances with one tool.
C++ ★ 0 1mo agoExplain → -
kernel-corpus
kernel-corpus
★ 0 18d agoExplain → -
RefineGoals
No description.
TypeScript ★ 0 1mo agoExplain → -
CastClip
Type-casting for your clipboard. Instantly format copied data into clean JSON, Markdown, YAML, SQL IN, and TSV.
TypeScript ★ 0 1mo agoExplain → -
windows-driver-docs ⑂
The official Windows Driver Kit documentation sources
PowerShell ★ 0 8y agoExplain → -
focus-on
FocusOn is an ultra-lightweight, high-performance distraction dimmer utility for Windows, written entirely in Rust. It helps you focus on your current task by dimming inactive screens and background windows, keeping only the active window illuminated.
Rust ★ 0 1mo agoExplain → -
my-local-event-calendar
전국의 전시·축제·공연·팝업스토어 일정을 지도 + 캘린더로 한눈에 보여주는 서비스
TypeScript ★ 0 1mo agoExplain → -
my-teacher
AI 기반 영어 발음 교정 웹 애플리케이션
TypeScript ★ 0 1mo agoExplain → -
dewdrop-canvas
A Tactile Liquid Brain-Mapping & Generative AI Thought Synthesis Board
JavaScript ★ 0 1mo agoExplain → -
windchill
A premium native desktop wellness station and procedural ambient sound synthesizer designed to prevent computer fatigue, restore cognitive focus, and guide you through calming somatic rest cycles.
JavaScript ★ 0 2mo agoExplain → -
DrvMon ⑂
Advanced driver monitoring utility.
★ 0 4y agoExplain → -
DropCast
Local bridging service that instantly shares files bidirectionally between mobile and Windows PC inside the same network environment—wire-free, account-free, and setup-free.
JavaScript ★ 0 2mo agoExplain → -
my-steelman
Steelman Counter-Argument Generator — AI-driven debate adversary
HTML ★ 0 2mo agoExplain → -
CodeChingu
AI Coding Assistant Extension for Visual Studio
C# ★ 0 2mo agoExplain → -
into-the-git
Multi-repo code analysis dashboard with AST parsing, open-source linter integration (cppcheck/pylint/PMD/ESLint), ML-based commit purpose classification, and hybrid feedback scoring. On-premises Flask app.
Python ★ 0 2mo agoExplain → -
cloud-hypervisor ⑂
A Virtual Machine Monitor for modern Cloud workloads. Features include CPU, memory and device hotplug, support for running Windows and Linux guests, device offload with vhost-user and a minimal compact footprint. Written in Rust with a strong focus on security.
★ 0 2mo agoExplain → -
Codex-get-some-rest
Let Codex finish long-running work, say thanks, and shut down your PC.
JavaScript ★ 0 2mo agoExplain → -
BriefWave-Cast
BriefWave Cast is a Korean AI news podcast generator powered by Gemini, ElevenLabs, and FastAPI.
Python ★ 0 2mo agoExplain → -
merge_xlsm
merge 2 xlsm files into 1 xlsm file.
Python ★ 0 3mo agoExplain → -
creative-writing-assistant
A comprehensive tool for analyzing and enhancing creative writing with AI-powered insights.
Python ★ 0 3mo agoExplain → -
G0DM0D3 ⑂
LIBERATED AI CHAT
★ 0 4mo agoExplain → -
open-agents ⑂
An open source template for building cloud agents.
★ 0 3mo agoExplain → -
magika ⑂
Fast and accurate AI powered file content types detection
★ 0 3mo agoExplain → -
knsymphony ⑂
Symphony turns project work into isolated, autonomous implementation runs, allowing teams to manage work instead of supervising coding agents.
★ 0 3mo agoExplain → -
sogen ⑂
🪅 Windows User Space Emulator
★ 0 4mo agoExplain → -
Rikugan ⑂
A reverse-engineering agent for IDA Pro and Binary Ninja
★ 0 4mo agoExplain → -
Stardust ⑂
A modern 32/64-bit position independent implant template
★ 0 1y agoExplain → -
GitNexus ⑂
GitNexus: The Zero-Server Code Intelligence Engine - GitNexus is a client-side knowledge graph creator that runs entirely in your browser. Drop in a GitHub repo or ZIP file, and get an interactive knowledge graph wit a built in Graph RAG Agent. Perfect for code exploration
★ 0 4mo agoExplain → -
Nidhogg ⑂
Nidhogg is an all-in-one simple to use windows kernel rootkit.
★ 0 5mo agoExplain → -
sherlock ⑂
Intercept LLM API traffic and visualize token usage in a real-time terminal dashboard. Track costs, debug prompts, and monitor context window usage across your AI development sessions.
★ 0 5mo agoExplain → -
clawdbot ⑂
Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞
★ 0 5mo agoExplain → -
ShadeOfColor2 ⑂
A simple cross-platform tool to hide files inside PNG images
★ 0 10mo agoExplain → -
CreateProcessAsPPL ⑂
This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.
★ 0 10mo agoExplain → -
EDR-Freeze ⑂
EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.
★ 0 10mo agoExplain → -
obex ⑂
Obex – Blocking unwanted DLLs in user mode
★ 0 10mo agoExplain → -
MFTool ⑂
Direct access to NTFS volumes
★ 0 10mo agoExplain → -
KittyLoader ⑂
KittyLoader is a highly evasive loader written in C / Assembly
★ 0 10mo agoExplain → -
VectorKernel ⑂
PoCs for Kernelmode rootkit techniques research.
★ 0 10mo agoExplain → -
Vtl1Mon ⑂
Virtual Trust Level (VTL 1) secure call tracing
★ 0 11mo agoExplain → -
TrapFlagForSyscalling ⑂
Bypass user-land hooks by syscall tampering via the Trap Flag
★ 0 11mo agoExplain → -
ETWLocksmith ⑂
A powerful Windows command-line tool for analyzing and searching ETW (Event Tracing for Windows) provider permissions from the Windows registry.
★ 0 1y agoExplain → -
dumping_lsass ⑂
The different ways to dump lsass
★ 0 11mo agoExplain → -
BlockEDRTraffic ⑂
Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows Filtering Platform (WFP).
★ 0 11mo agoExplain → -
BamboozlEDR ⑂
A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.
★ 0 11mo agoExplain → -
Hells-Hollow ⑂
Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls
★ 0 11mo agoExplain → -
EDRs ⑂
No description.
★ 0 3y agoExplain → -
waiting_thread_hijacking ⑂
Waiting Thread Hijacking - injection by overwriting the return address of a waiting thread
★ 0 1y agoExplain → -
LdrShuffle ⑂
Code execution/injection technique using DLL PEB module structure manipulation
★ 0 1y agoExplain → -
DreamWalkers ⑂
Reflective shellcode loaderwith advanced call stack spoofing and .NET support.
★ 0 1y agoExplain → -
Full-Kernel-Driver ⑂
No description.
★ 0 5y agoExplain → -
EKFiddle ⑂
A framework to study Exploit Kits
C# ★ 0 8y agoExplain → -
BugChecker ⑂
SoftICE-like kernel debugger for Windows 11
★ 0 3y agoExplain → -
goffloader ⑂
A Go implementation of Cobalt Strike style BOF/COFF loaders.
★ 0 1y agoExplain → -
NamedPipeMaster ⑂
a tool used to analyze and monitor in named pipes
★ 0 1y agoExplain → -
CVE-2024-26229 ⑂
CWE-781: Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code
★ 0 2y agoExplain → -
KernelForge ⑂
A library to develop kernel level Windows payloads for post HVCI era
★ 0 5y agoExplain → -
ZeroHVCI ⑂
Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers.
★ 0 2y agoExplain → -
AsmHalosGate ⑂
x64 Assembly HalosGate direct System Caller to evade EDR UserLand hooks
★ 0 3y agoExplain → -
DarkWidow ⑂
Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a sacrificial Process as target process + (ACG+BlockDll) mitigation policy on spawned process + PPID spoofing + Api resolving from TIB + API hashing
★ 0 2y agoExplain → -
linjector-rs ⑂
Code injection on Android without ptrace
★ 0 2y agoExplain → -
Offensive-OSINT-Tools ⑂
OffSec OSINT Pentest/RedTeam Tools
★ 0 2y agoExplain → -
go-secdump ⑂
Tool to remotely dump secrets from the Windows registry
★ 0 2y agoExplain → -
ADPT ⑂
DLL proxying for lazy people
★ 0 2y agoExplain → -
Yumekage ⑂
Demo proof of concept for shadow regions, and implementation of HyperDeceit.
★ 0 3y agoExplain → -
BottlEye ⑂
BottlEye is a usermode emulator for the popular anti-cheat BattlEye
★ 0 6y agoExplain → -
eagle-rs ⑂
Rusty Rootkit: Windows Kernel Driver in Rust for Red Teamers
★ 0 3y agoExplain → -
winapi-rs ⑂
Rust bindings to Windows API
★ 0 7y agoExplain → -
Gepetto ⑂
IDA plugin which queries OpenAI's davinci-003 language model to speed up reverse-engineering
★ 0 3y agoExplain → -
ALPC-Example ⑂
An example of a client and server using Windows' ALPC functions to send and receive data.
★ 0 6y agoExplain → -
portaudio ⑂
PortAudio is a cross-platform, open-source C language library for real-time audio input and output.
★ 0 3y agoExplain → -
Kernel-Overlay-Hider ⑂
No description.
★ 0 3y agoExplain → -
boiii ⑂
☄️ Reverse engineering and analysis of Call of Duty: Black Ops III
★ 0 3y agoExplain → -
wnfexec ⑂
WNF Code Execution Library Using C#
★ 0 6y agoExplain → -
ntoskrnl_file_collection ⑂
Collect various versions of ntoskrnl files
★ 0 3y agoExplain → -
FUD-UUID-Shellcode ⑂
No description.
★ 0 3y agoExplain → -
Mangle ⑂
Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs
★ 0 3y agoExplain → -
AtomPePacker ⑂
A Highly capable Pe Packer
★ 0 3y agoExplain → -
VmwareHardenedLoader ⑂
Vmware Hardened VM detection mitigation loader (anti anti-vm)
★ 0 3y agoExplain → -
CosMapper ⑂
Loads a signed kernel driver which allows you to map any driver to kernel mode without any traces of the signed / mapped driver.
★ 0 5y agoExplain → -
KDU ⑂
Kernel Driver Utility
C ★ 0 3y agoExplain → -
NoScreen ⑂
Hiding the window from screenshots using the function win32kfull::GreProtectSpriteContent
★ 0 4y agoExplain → -
kernelhook ⑂
Windows inline hooking tool.
★ 0 7y agoExplain → -
dwm_overlay ⑂
PoC: DX11 overlay over DWM
★ 0 6y agoExplain → -
dwmhook ⑂
noob hooking dwm for overlay
★ 0 5y agoExplain → -
kernel-csgo ⑂
Kernel cheat with kernel hook for communication
★ 0 5y agoExplain → -
Windows10EtwEvents ⑂
Events from all manifest-based and mof-based ETW providers across Windows 10 versions
★ 0 4y agoExplain → -
WinToast ⑂
WinToast is a lightly library written in C++ which brings a complete integration of the modern toast notifications of Windows 8 & Windows 10. Toast notifications allows your app to inform the users about relevant information and timely events that they should see and take action upon inside your app, such as a new instant message, a new friend request, breaking news, or a calendar event.
★ 0 4y agoExplain → -
etw-providers-docs ⑂
Document ETW providers
★ 0 6y agoExplain → -
concealed_code_execution ⑂
Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows
★ 0 4y agoExplain → -
DotDumper ⑂
An automatic unpacker and logger for DotNet Framework targeting files
★ 0 4y agoExplain → -
CustomProcessingUnit ⑂
The first dynamic analysis framework for CPU microcode
★ 0 4y agoExplain → -
formatPE ⑂
A bunch of parsers for PE and PDB formats in C++
★ 0 4y agoExplain → -
VehApiResolve ⑂
No description.
★ 0 4y agoExplain → -
DarkLoadLibrary ⑂
LoadLibrary for offensive operations
★ 0 4y agoExplain → -
VolatileDataCollector ⑂
No description.
★ 0 4y agoExplain → -
CreateProcess ⑂
A small PoC that creates processes in Windows
★ 0 4y agoExplain → -
MalwareApiLibrary ⑂
collection of apis used in malware development
★ 0 4y agoExplain → -
ida_bochs_windows ⑂
Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)
★ 0 4y agoExplain → -
system_call_hook_win10_1903 ⑂
This is the P.O.C source for hooking the system calls on Windows 10 (1903) using it's dynamic trace feature weakness
★ 0 6y agoExplain → -
RIPPL ⑂
RIPPL is a tool that abuses a usermode only exploit to manipulate PPL processes on Windows
★ 0 4y agoExplain → -
MicrocodeDecryptor ⑂
No description.
★ 0 4y agoExplain → -
unlicense ⑂
Dynamic unpacker and import fixer for Themida/WinLicense 2.x and 3.x.
★ 0 4y agoExplain → -
ollvm-13 ⑂
obfuscator-llvm 移植到llvm13
★ 0 4y agoExplain → -
VX-API ⑂
Malware rapid development framework
★ 0 4y agoExplain → -
AntimalwareBlight ⑂
Execute PowerShell code at the antimalware-light protection level.
★ 0 4y agoExplain → -
DInjector ⑂
Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL
★ 0 4y agoExplain → -
donut ⑂
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
★ 0 4y agoExplain → -
Shark ⑂
Turn off PatchGuard in real time for win7 (7600) ~ later
★ 0 4y agoExplain → -
KernelCallbackTable-Injection ⑂
Code used in this post https://captmeelo.com/redteam/maldev/2022/04/21/kernelcallbacktable-injection.html
★ 0 4y agoExplain → -
InterProcessCommunication-Samples ⑂
Some Code Samples for Windows based Inter-Process-Communication (IPC)
★ 0 4y agoExplain → -
open-gpu-kernel-modules ⑂
NVIDIA Linux open GPU kernel module source
★ 0 4y agoExplain → -
RECmd ⑂
Command line access to the Registry
★ 0 4y agoExplain → -
Registry ⑂
Full featured, offline Registry parser in C#
★ 0 4y agoExplain → -
huffman-coding ⑂
A C++ compression and decompression program based on Huffman Coding.
★ 0 6y agoExplain → -
ntfstool ⑂
Forensics tool for NTFS (parser, mft, bitlocker, deleted files)
★ 0 4y agoExplain → -
regf ⑂
Windows registry file format specification
★ 0 7y agoExplain → -
ept-hook-detection ⑂
Different aproaches to detecting EPT hooks
★ 0 4y agoExplain → -
hypervisor ⑂
Hypervisor and EPT hooking experiments.
★ 0 4y agoExplain → -
kdmapper-1 ⑂
KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory
★ 0 4y agoExplain → -
UnrealDumper-4.25 ⑂
No description.
★ 0 4y agoExplain → -
MapPage ⑂
Mapping your code on a 0x1000 size page
★ 0 4y agoExplain → -
eac-mapper ⑂
undetected eac mapper
★ 0 4y agoExplain → -
Rw-No-Attach ⑂
No description.
★ 0 4y agoExplain → -
UE3SDKGenerator ⑂
Internal SDK generator for Unreal Engine 3 games.
★ 0 4y agoExplain → -
drvmap ⑂
driver mapper / capcom wrapper
★ 0 6y agoExplain → -
srum-dump ⑂
A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.
★ 0 4y agoExplain → -
Prefetch ⑂
Windows Prefetch parser. Supports all known versions from Windows XP to Windows 10.
★ 0 4y agoExplain → -
ShimCacheParser ⑂
No description.
★ 0 6y agoExplain → -
AppCompatCacheParser ⑂
AppCompatCache (shimcache) parser. Supports Windows 7 (x86 and x64), Windows 8.x, and Windows 10
★ 0 4y agoExplain → -
Volatility-Plugins ⑂
No description.
★ 0 10y agoExplain → -
EventTranscript.db-Research ⑂
A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
★ 0 4y agoExplain → -
Shh0yaUEDumper ⑂
UEDumper
★ 0 5y agoExplain → -
KernelV ⑂
Rootkit & Anti-rootkit
★ 0 4y agoExplain → -
process_overwriting ⑂
Yet another variant of Process Hollowing
★ 0 4y agoExplain → -
bug-bounty ⑂
list of bug bounty writeups
★ 0 4y agoExplain → -
PSBits ⑂
Simple (mainly PowerShell) solutions allowing you to dig a bit deeper than usual.
PowerShell ★ 0 4y agoExplain → -
malware-gems ⑂
A not so awesome list of malware gems for aspiring malware analysts
★ 0 6y agoExplain → -
bulk_extractor ⑂
This is the development tree. Production downloads are at:
★ 0 4y agoExplain → -
hygieia ⑂
Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.
★ 0 4y agoExplain → -
pagewalkr ⑂
An x64 page table iterator written in C++ as a kernel mode windows driver.
★ 0 5y agoExplain → -
kdmapper ⑂
driver manual mapper (outdated/for educational purposes)
★ 0 7y agoExplain → -
KillDefender ⑂
A small POC to make defender useless by removing its token privileges and lowering the token integrity
★ 0 4y agoExplain → -
PPLGuard ⑂
No description.
★ 0 4y agoExplain → -
PrivFu ⑂
Kernel mode WinDbg extension and PoCs for token privilege investigation.
★ 0 4y agoExplain → -
Process-Hollowing ⑂
Great explanation of Process Hollowing (a Technique often used in Malware)
C++ ★ 0 4y agoExplain → -
process_ghosting ⑂
Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file
★ 0 4y agoExplain → -
Advanced-Process-Injection-Workshop ⑂
No description.
★ 0 4y agoExplain → -
transacted_hollowing ⑂
Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging
★ 0 4y agoExplain → -
Inject-dll-by-Process-Doppelganging ⑂
Process Doppelgänging
★ 0 8y agoExplain → -
antispy ⑂
AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its assistance,you can easily spot and neutralize malwares hidden from normal detectors.
★ 0 5y agoExplain → -
ARK ⑂
内核编程实践-ARK工具(AntiRootKit)
★ 0 6y agoExplain → -
ceload ⑂
Loading dbk64.sys and grabbing a handle to it
★ 0 4y agoExplain → -
SEAL ⑂
Simple Encrypted Arithmetic Library (SEAL) is an easy-to-use but powerful homomorphic encryption library written in C++. It supports both the BFV and the CKKS encryption schemes.
C++ ★ 0 4y agoExplain → -
ps4debug ⑂
PlayStation 4 Debugger
★ 0 6y agoExplain → -
UMPMLib ⑂
A library to manipulate physical memory from usermode.
★ 0 8y agoExplain → -
NO_ACCESS_Protection ⑂
No description.
★ 0 4y agoExplain → -
face-injector-v2 ⑂
update face injector by KANKOSHEV
★ 0 4y agoExplain → -
II-ExternalHookingLib ⑂
External Hooking ( Bypasss process byte patching checks | Injector included )
★ 0 4y agoExplain → -
Blackbone ⑂
Windows memory hacking library
★ 0 4y agoExplain → -
medusa ⑂
Binary instrumentation framework based on FRIDA
★ 0 4y agoExplain → -
ProcessHollowing ⑂
Simple Process Hollowing in C#
★ 0 8y agoExplain → -
runtimelab ⑂
This repo is for experimentation and exploring new ideas that may or may not make it into the main dotnet/runtime repo.
★ 0 4y agoExplain → -
ZeroKernel ⑂
Bringing kernel driver to C# with MichalStrehovsky's zerosharp
★ 0 4y agoExplain → -
KernelBypassSharp ⑂
C# Kernel Mode Driver to read and write memory in protected processes
★ 0 4y agoExplain → -
KernelSharp ⑂
C# Kernel Mode Driver example using NativeAOT
★ 0 4y agoExplain → -
capstone ⑂
Capstone disassembly/disassembler framework: Core (Arm, Arm64, M68K, Mips, PPC, Sparc, SystemZ, X86, X86_64, XCore) + bindings (Python, Java, Ocaml, PowerShell)
POV-Ray SDL ★ 0 9y agoExplain → -
speakeasy ⑂
Windows kernel and user mode emulation.
★ 0 5y agoExplain → -
SilkETW ⑂
No description.
C# ★ 0 7y agoExplain → -
kn-gloryo.github.io ⑂
Build a Jekyll blog in minutes, without touching the command line.
CSS ★ 0 10y agoExplain → -
Windows-2000 ⑂
Microsoft Windows 2000 Professional — (Source Codes)
★ 0 9y agoExplain → -
cutter ⑂
A Qt and C++ GUI for radare2 reverse engineering framework
C++ ★ 0 8y agoExplain → -
Reflective-Driver-Loader ⑂
No description.
★ 0 9y agoExplain → -
ImprovedReflectiveDLLInjection ⑂
An improvement of the original reflective DLL injection technique by Stephen Fewer of Harmony Security
★ 0 9y agoExplain → -
wow64Jit ⑂
Call 32bit NtDLL API directly from WoW64 Layer
★ 0 5y agoExplain → -
wil ⑂
Windows Implementation Library
★ 0 5y agoExplain → -
herpaderping ⑂
Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of a process.
★ 0 5y agoExplain → -
CallbackObjectAnalyzer ⑂
Dumps information about all the callback objects found in a dump file and the functions registered for them
★ 0 5y agoExplain →
No repos match these filters.