Pinned Repositories
Avast-Reverse-Engineering
Pseudocodes of various Avast antivirus files are collected here. (DLL, SYS)! Abandoned collaboration with @colby57
Calamity
Example of using Windows Platform Binary Table (WPBT)
Deadwing
SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.
KernelBeep
HalMakeBeep
MilkBox
Tool to dump EFI runtime drivers.
MiniMemoryDumper
A small program written in C + WinAPI that allows you to dump processes via PID.
PicoHook
Small driver that uses alternative syscalls feature (the project is still under development).
recycle-bin-themes
Silly icons for the Windows Recycle Bin
ResilienceKit
Another UEFI runtime bootkit
smm
alternative smm driver for ryzen motherboards
xsh3llsh0ck's Repositories
xsh3llsh0ck/Deadwing
SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.
xsh3llsh0ck/xsh3llsh0ck
xsh3llsh0ck/PicoHook
Small driver that uses alternative syscalls feature (the project is still under development).
xsh3llsh0ck/MilkBox
Tool to dump EFI runtime drivers.
xsh3llsh0ck/smm
alternative smm driver for ryzen motherboards
xsh3llsh0ck/Calamity
Example of using Windows Platform Binary Table (WPBT)
xsh3llsh0ck/ResilienceKit
Another UEFI runtime bootkit
xsh3llsh0ck/Avast-Reverse-Engineering
Pseudocodes of various Avast antivirus files are collected here. (DLL, SYS)! Abandoned collaboration with @colby57
xsh3llsh0ck/TheSleeper
Custom analog of Sleep function from WinAPI.
xsh3llsh0ck/winrev
Some reverse-engineered things from windows internals
xsh3llsh0ck/minhook
The Minimalistic x86/x64 API Hooking Library for Windows
xsh3llsh0ck/MiniMemoryDumper
A small program written in C + WinAPI that allows you to dump processes via PID.
xsh3llsh0ck/KernelBeep
HalMakeBeep
xsh3llsh0ck/recycle-bin-themes
Silly icons for the Windows Recycle Bin
xsh3llsh0ck/AFLplusplus
The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!
xsh3llsh0ck/DummyDevice
xsh3llsh0ck/core_analyzer
A power tool to debug memory-related issues