Cr4sh
😈 zero-fucks-given infosec research | info: 🔗 keybase.io/d_olex | 🇺🇦 Ukraine needs your help to kill Ruϟϟian zombies: 🔗 savelife.in.ua/en/donate 💪
Pinned Repositories
Aptiocalypsis
Arbitrary SMM code execution exploit for industry-wide 0day vulnerability in AMI Aptio based firmwares
KernelForge
A library to develop kernel level Windows payloads for post HVCI era
MicroBackdoor
Small and convenient C2 tool for Windows targets. [ Русский -- значит нахуй! ]
openreil
Open source library that implements translator and tools for REIL (Reverse Engineering Intermediate Language)
pico_dma
Autonomous pre-boot DMA attack hardware implant for M.2 slot based on PicoEVB development board
s6_pcie_microblaze
PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info
SmmBackdoor
First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM experiments.
SmmBackdoorNg
Updated version of System Management Mode backdoor for UEFI based platforms: old dog, new tricks
ThinkPwn
Started as arbitrary System Management Mode code execution exploit for Lenovo ThinkPad model line, ended as exploit for industry-wide 0day vulnerability in machines of many vendors
WindowsRegistryRootkit
Kernel rootkit, that lives inside the Windows registry values data
Cr4sh's Repositories
Cr4sh/s6_pcie_microblaze
PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info
Cr4sh/ThinkPwn
Started as arbitrary System Management Mode code execution exploit for Lenovo ThinkPad model line, ended as exploit for industry-wide 0day vulnerability in machines of many vendors
Cr4sh/MicroBackdoor
Small and convenient C2 tool for Windows targets. [ Русский -- значит нахуй! ]
Cr4sh/SmmBackdoor
First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM experiments.
Cr4sh/openreil
Open source library that implements translator and tools for REIL (Reverse Engineering Intermediate Language)
Cr4sh/WindowsRegistryRootkit
Kernel rootkit, that lives inside the Windows registry values data
Cr4sh/KernelForge
A library to develop kernel level Windows payloads for post HVCI era
Cr4sh/SmmBackdoorNg
Updated version of System Management Mode backdoor for UEFI based platforms: old dog, new tricks
Cr4sh/fwexpl
PC firmware exploitation tool and library
Cr4sh/PeiBackdoor
PEI stage backdoor for UEFI compatible firmware
Cr4sh/ioctlfuzzer
Automatically exported from code.google.com/p/ioctlfuzzer
Cr4sh/UEFI_boot_script_expl
CHIPSEC module that exploits UEFI boot script table vulnerability
Cr4sh/smram_parse
System Management RAM analysis tool
Cr4sh/pico_dma
Autonomous pre-boot DMA attack hardware implant for M.2 slot based on PicoEVB development board
Cr4sh/Aptiocalypsis
Arbitrary SMM code execution exploit for industry-wide 0day vulnerability in AMI Aptio based firmwares
Cr4sh/zc_pcie_dma
DMA attacks over PCI Express based on Xilinx Zynq-7000 series SoC
Cr4sh/qc_debug_monitor
Debug messages monitor for Qualcomm cellular modems
Cr4sh/secretnet_expl
LPE exploits for Secret Net and Secret Net Studio
Cr4sh/DbgCb
Engine for communication with remote kernel debugger (KD, WinDbg) from drivers and applications
Cr4sh/prl_guest_to_host
Guest to host VM escape exploit for Parallels Desktop
Cr4sh/IDA-UbiGraph
IDA Pro plug-in and tools for displaying 3D graphs of procedures using UbiGraph
Cr4sh/efiXplorer
IDA plugin for UEFI firmware analysis and reverse engineering automation
Cr4sh/r0ak
r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems
Cr4sh/blog
Stuff for blog.cr4.sh website
Cr4sh/capstone
Capstone disassembly/disassembler framework: Core (Arm, Arm64, Mips, PPC, Sparc, SystemZ, X86, X86_64, XCore) + bindings (Python, Java, Ocaml)
Cr4sh/masscan
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
Cr4sh/PowerShell-Suite
My musings with PowerShell
Cr4sh/chipsec
Platform Security Assessment Framework
Cr4sh/portage
Portage Package Manager - this is just a mirror, see https://wiki.gentoo.org/wiki/Project:Portage#Contributing_to_Portage
Cr4sh/vmlinux-to-elf
A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)