Pinned Repositories
BlairInjector
Ring0 meme wey
HdeWrapper
Find your offsets the cool way, :)
InterDKOM
Kernelmode driver with hijacked IOCTL payload, physical memory support and DTB bruteforce
pipedriver
Communicate from ring-0 to ring-3 using NamedPipes.
ssdtmeme
Demonstrates SSDT hooking, technique often used by BattlEye. Only works in ring-0 privileges
ValorantOffsets
Always updated and freshly dumped with HdeWrapper
wardenrekter
Emulate OW2 AC
blair1922's Repositories
blair1922/BlairInjector
Ring0 meme wey
blair1922/pipedriver
Communicate from ring-0 to ring-3 using NamedPipes.
blair1922/HdeWrapper
Find your offsets the cool way, :)
blair1922/wardenrekter
Emulate OW2 AC
blair1922/ssdtmeme
Demonstrates SSDT hooking, technique often used by BattlEye. Only works in ring-0 privileges
blair1922/InterDKOM
Kernelmode driver with hijacked IOCTL payload, physical memory support and DTB bruteforce
blair1922/VulnKernelDriver-GLC
blair1922/ValorantOffsets
Always updated and freshly dumped with HdeWrapper
blair1922/EasyAntiCheat-Emulator
Simple DLL that spoofs EasyAntiCheat on most games
blair1922/smart-uefi
communicate through EFI variables without an EFI driver
blair1922/Base
blair1922/OnlyCerts-POC
Whitelist certificates from ring3, cba add integrity checks to prevent program for being tampered with
blair1922/shmb
runtime shared memory ring0 example
blair1922/Awesome-Bootkits-Rootkits-Development
A curated compilation of extensive resources dedicated to bootkit and rootkit development.
blair1922/BlackLotus
BlackLotus UEFI Windows Bootkit
blair1922/blairhv
x64 intel hypervisor with vmcs, vmx and physical page support
blair1922/EfiCMake
CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).
blair1922/FecurityCODWebApi
Run on flask on VPS, used for auto page translation
blair1922/Hyper-V-scripts
Hyper-V scripts
blair1922/Memeory
Unlock paging table accesses on Windows.
blair1922/memflow
physical memory introspection framework
blair1922/ultracage
Config files for my GitHub profile.
blair1922/umap
Temp repo to spoof btbd/umap edit date
blair1922/unvirt_driver
tested on vgk
blair1922/vmread-rs
Rust bindings for vmread
blair1922/W10M_unedited-decomp
Pure Hex-rays Decompiler Psudocode of various Windows 10 Mobile binaries, No edit have been done to the output, you will need to piece together each function, class etc.Provided "as-is"