Pinned Repositories
DSEFix
Windows x64 Driver Signature Enforcement Overrider
KDU
Kernel Driver Utility
LightFTP
Small x86-32/x64 FTP Server
NtCall64
Windows NT x64 syscall fuzzer
SyscallTables
Windows NT Syscall tables
TDL
Driver loader for bypassing Windows x64 Driver Signature Enforcement
UACME
Defeating Windows User Account Control
UPGDSED
Universal PatchGuard and Driver Signature Enforcement Disable
VBoxHardenedLoader
VirtualBox VM detection mitigation loader
WinObjEx64
Windows Object Explorer 64-bit
hfiref0x's Repositories
hfiref0x/UACME
Defeating Windows User Account Control
hfiref0x/KDU
Kernel Driver Utility
hfiref0x/WinObjEx64
Windows Object Explorer 64-bit
hfiref0x/SyscallTables
Windows NT Syscall tables
hfiref0x/TDL
Driver loader for bypassing Windows x64 Driver Signature Enforcement
hfiref0x/VBoxHardenedLoader
VirtualBox VM detection mitigation loader
hfiref0x/UPGDSED
Universal PatchGuard and Driver Signature Enforcement Disable
hfiref0x/DSEFix
Windows x64 Driver Signature Enforcement Overrider
hfiref0x/NtCall64
Windows NT x64 syscall fuzzer
hfiref0x/WDExtract
Extract Windows Defender database from vdm files and unpack it
hfiref0x/WubbabooMark
Debugger Anti-Detection Benchmark
hfiref0x/CVE-2015-1701
Win32k LPE vulnerability used in APT attack
hfiref0x/LightFTP
Small x86-32/x64 FTP Server
hfiref0x/VMDE
Source from VMDE paper, adapted to 2015
hfiref0x/ZeroAccess
ZeroAccess v3 toolkit
hfiref0x/SXSEXP
Expand compressed files from WinSxS folder
hfiref0x/AuthHashCalc
Authenticode Hash Calculator for PE32/PE32+ files
hfiref0x/Stryker
Multi-purpose proof-of-concept tool based on CPU-Z CVE-2017-15303
hfiref0x/MpEnum
Enumerate Windows Defender threat families and dump their names according category
hfiref0x/Misc
Miscellaneous Code and Docs
hfiref0x/ROCALL
ReactOS x86-32 syscall fuzzer
hfiref0x/BSODScreen
BSOD Screensaver
hfiref0x/al-khaser
(This is a fork used primarily to submit patches into upstream repository) Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
hfiref0x/AsIo3Unlock
ASUSTeK AsIO3 I/O driver unlock
hfiref0x/RpcView
(This is a fork used primarily to submit patches into upstream repository) RpcView is a free tool to explore and decompile Microsoft RPC interfaces
hfiref0x/LightFTP_win
hfiref0x/hfiref0x.github.io
hfiref0x/Vault
Various code from the past (for historical purposes)
hfiref0x/pdbex
(This is a fork used primarily to submit patches into upstream repository) pdbex is a utility for reconstructing structures and unions from the PDB into compilable C headers
hfiref0x/AR4FFC
Archive repository for fast fact-checks