Here are
36 public repositories
matching this topic...
Windows File System Proxy - FUSE for Windows
A modern tool for the Windows kernel exploration and tracing
State-of-the-art native debugging tool
Intel VT-x based hypervisor aiming to provide a thin VM-exit filtering platform on Windows.
Windows Storage Proxy Driver - User mode disk storage
Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.
kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x
SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.
C++ STL in the Windows Kernel with C++ Exception Support
A minimalistic educational hypervisor for Windows on AMD processors.
The Universal C++ RunTime library, supporting kernel-mode C++ exception-handler and STL.
A native hypervisor designed for the Windows operating system
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks
Updated
Dec 15, 2021
Python
Enumerate user mode shared memory mappings on Windows.
Kernel mode WinDbg extension and PoCs for token privilege investigation.
CSharp Writeups for HackSys Extreme Vulnerable Driver
Driver demonstrating how to register a DPC to asynchronously wait on an object
Call arbitrary Windows kernel-mode functions from Python on another machine
Updated
Sep 17, 2021
Python
C# Utilities for Windows Notification Facility
Example Windows Kernel-mode Driver which enumerates running processes.
A POC for Windows Extension Host hooking
🔍 Code to read / write the Process Memory from the Kernel 🔧
Very tiny and selective implementation of STL for Windows NT kernel mode drivers
improving zerosums smbdoor - a silent remote backdoor which abuses undoc. APIs in srvnet.sys
A proof of concept demonstrating communication via mapped shared memory structures between a user-mode process and a kernel-mode payload on Windows 10 20H2.
A driver that supports communication between a Windows guest and HyperWin
WinPools is an example of how Windows kernel big pool addresses can be leaking using NtQuerySystemInformation
Lot of Walkers under Windows.
Windows Kernel-Mode Drivers written in Rust
Updated
Sep 13, 2017
Rust
Improve this page
Add a description, image, and links to the
windows-kernel
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
windows-kernel
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.