zfdyq0's Stars
ExpLife0011/awesome-windows-kernel-security-development
windows kernel security development
ReClassNET/ReClass.NET
More than a ReClass port to the .NET platform.
Cybellum/DoubleAgent
Zero-Day Code Injection and Persistence Technique
ClownQq/YDArk
X64内核小工具
9176324/Shark
Turn off PatchGuard in real time for win7 (7600) ~ later
Mattiwatti/PPLKiller
Protected Processes Light Killer
can1357/ThePerfectInjector
Literally, the perfect injector.
hfiref0x/DSEFix
Windows x64 Driver Signature Enforcement Overrider
adrianyy/rw_socket_driver
Driver that uses network sockets to communicate with client and read/ write protected process memory.
danielkrupinski/MemJect
Simple Dll injector loading from memory. Supports PE header and entry point erasure. Written in C99.
antiwar3/py
飘云ark(pyark)
can1357/CVE-2018-8897
Arbitrary code execution with kernel privileges using CVE-2018-8897.
ln93/kosmos_chs_tutorial
A Chinese version tutorial about installing kosmos
0xcpu/ExecutiveCallbackObjects
Research on Windows Kernel Executive Callback Objects
M-r-J-o-h-n/SWH-Injector
An Injector that can inject dll into game process protected by anti cheat using SetWindowsHookEx.
0vercl0k/kdmp-parser
A Windows kernel dump C++ parser library with Python 3 bindings.
Schnocker/HLeaker
An usermode alternative for DuplicateHandle.
notscimmy/pplib
Elevate a process to be a protected process
vmcall/x64-vm
x86-64 virtual machine and disassembler
zzhouhe/PG1903
ContionMig/LSASS-Usermode-Bypass
This bypass is for anti cheats like battleye and EAC. All this does is abuse lsass's handles and use them for yourself. This is quite useful as this is usermode which doesnt require you to find a way to load a driver
zhuhuibeishadiao/PatchGuardResearch
win10 pgContext dynamic dump (btc version)
yardenshafir/SymlinkCallback
A driver that hooks C: volume using symbolic link callback to track all FS access to the volume
zouxianyu/PhysicalMemoryRW
the basic version of the ring0 physical memory read/write tool
fengjixuchui/SharedMemory-By-Frankoo
Kernel driver that uses Shared memory to communicate with UserMode
vasco2016/shellsploit-framework
New Generation Exploit Development Kit
notscimmy/libinject
Currently supports injecting signed/unsigned DLLs in 64-bit processes
matias-kovero/tarkov
A npm library for the Escape from Tarkov API
M-r-J-o-h-n/Driver-Manual-Mapper
M-r-J-o-h-n/LSASS-injector
LSASS INJECTOR