Pinned Repositories
010Editor-keygen
A keygen for 010Editor
64KernelDriverCleaner
A Kernel Driver that can be used for a cheat or malware base to circumvent common cache & structure table checks. PsLoadedModuleList however requires a PG Bypass on (Some) Machines > 22H2 Win10, Not Win 11
ac
wip anti cheat
acdrv
base for testing
AceLdr
Cobalt Strike UDRL for memory scanner evasion.
Advanced-Process-Injection-Workshop
ALPC-Port
Luramas
Retargetable Multiple Interpreted Languages Decompiler and Bytecode Analysis and Manipulation Framework
Ollvm18
xrv3ovl's Repositories
xrv3ovl/64KernelDriverCleaner
A Kernel Driver that can be used for a cheat or malware base to circumvent common cache & structure table checks. PsLoadedModuleList however requires a PG Bypass on (Some) Machines > 22H2 Win10, Not Win 11
xrv3ovl/AntiBootkit
User mode C++ tool for detecting UEFI drivers, bootkit malware and modifications by checking the Windows bootloader and managing BCD
xrv3ovl/ATDCM64a-LPE
xrv3ovl/BinaryShield
An x86-64 Code Virtualizer
xrv3ovl/BOAZ_beta
Multilayered AV/EDR Evasion Framework
xrv3ovl/COMThanasia
A set of programs for analyzing common vulnerabilities in COM
xrv3ovl/covirt
An x86-64 code virtualizer for VM based obfuscation
xrv3ovl/CVE-2024-30090
CVE-2024-30090 - LPE PoC
xrv3ovl/CVE-2024-49138-POC
POC exploit for CVE-2024-49138
xrv3ovl/defender2yara
Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules
xrv3ovl/defender_signature_parser
Short Python script for parsing Defender VDM signature files.
xrv3ovl/edk2-visualstudio
Develop UEFI applications using EDK II inside Visual Studio
xrv3ovl/HyperDbg
State-of-the-art native debugging tools
xrv3ovl/hypervisor
Hypervisor with EPT hooking support.
xrv3ovl/kananlib
xrv3ovl/limoncello
Yet another LLVM-based obfuscator
xrv3ovl/map
std::map implementation with RTL_AVL_TABLE
xrv3ovl/MentalTi
Mentally ill EtwTi parser
xrv3ovl/NamedPipeMaster
a tool used to analyze and monitor in named pipes
xrv3ovl/PdFwKrnlMapper
An Unsigned Driver Mapper for Windows 10 22H2 -> Windows 11 23H2 that uses PdFwKrnl to exploit the Read/Write IOCTL Calls to disable DSE & PG to map the unsigned driver.
xrv3ovl/RansomGuard
anti-ransomware file-system filter
xrv3ovl/RedEdr
Collect Windows telemetry for Maldev
xrv3ovl/sanctum
Sanctum is a proof-of-concept EDR like tool, designed to detect modern malware techniques, above and beyond the capabilities of antivirus. Built in Rust.
xrv3ovl/SKLib
Standard Kernel Library for Windows hacking in C++
xrv3ovl/solan
xrv3ovl/Sunder
Windows rootkit designed to work with BYOVD exploits
xrv3ovl/vcpu
xrv3ovl/vmw-logger-rs
A VMWare logger using built-in backdoor.
xrv3ovl/WRK
Windows Research Kernel VS2022 Solution
xrv3ovl/x86Tester
x86-64 Automated test data generator