Type-2 Intel hypervisor for Windows 10 systems
Updated 2 years ago
hook all win32k syscalls with a single .data pointer swap
Updated 2 years ago
swap driver on disk and memory with a Microsoft driver.
Updated 2 years ago
inserts a PML4E where a prior PML4E is set to not present, pointing at the PDPT that contains the dll.
Updated 2 years ago
old probe from 6/xx/2020 to test theoretical page table concepts
Updated 2 years ago
run code in an address space not associated with a process.
Updated 2 years ago
/proc/kmem reimplementation for windows
Updated 2 years ago
Process Cloning
Updated 2 years ago
inject a process into your context.
Updated 2 years ago
Vulnerable Driver Manipulation
Updated 2 years ago
Process-Context Specific Kernel Driver Mapper (PSKDM)
Updated 2 years ago
header only library for NtLoadDriver/NtUnloadDriver.
Updated 2 years ago
unfairgames reverse engineered.
Updated 2 years ago
header only library for manually mapping dll's.
Updated 2 years ago
driver dumper for manually mapped drivers mapped with kdmapper.
Updated 2 years ago