Skip to content
View focuspadding's full-sized avatar

Block or report focuspadding

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

WindowsSecurity

Windows逆向编程、分析等
315 repositories

neat way to detect memory read using nt layer function.

C++ 14 4 Updated Aug 4, 2023

"libcpu" is an open source library that emulates several CPU architectures

C++ 362 59 Updated Aug 21, 2021

Dont Call Me Back - Dynamic kernel callback resolver. Scan kernel callbacks in your system in a matter of seconds!

C 223 29 Updated Jul 9, 2024

Leaked Windows processes handles identification tool

C++ 272 42 Updated Mar 14, 2022

x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration

C++ 222 59 Updated Jul 6, 2022

A PoC for Mhyprot2.sys vulnerable driver that allowing read/write memory in kernel/user via unprivileged user process.

C++ 316 69 Updated Jul 3, 2021

A kernel vulnerability used to achieve arbitrary read-write on Windows prior to July 2022

C 105 30 Updated Nov 23, 2022

Quick check of NT kernel exported&unexported functions/global variable offset NT内核导出以及未导出函数+全局变量偏移速查

C++ 91 21 Updated Mar 30, 2023

Kernel Anit Anit Debug Plugins 内核反反调试插件

C++ 448 174 Updated Aug 31, 2021

The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).

C++ 232 82 Updated Mar 25, 2024

makin - reveal anti-debugging and anti-VM tricks [This project is not maintained anymore]

C++ 732 147 Updated Mar 17, 2019

CPU Internals (Cache, TLB, MMU, Pipeline, Branch Prediction, Out-of-Order Execution, ROB, Side Channel Attack ...)

C++ 23 5 Updated Aug 21, 2020

kernel-mode cs:go cheat without the need of a user-mode controller.

C++ 18 5 Updated Dec 22, 2022

Valve Anti-Cheat bypass written in C.

C 550 104 Updated Sep 23, 2021

Windows memory hacking library

C++ 4,855 1,336 Updated Jan 26, 2024

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

C++ 3,101 433 Updated Nov 6, 2024

CMake integration in Visual Studio Code

TypeScript 1,473 454 Updated Nov 14, 2024

Infect Shared Files In Memory for Lateral Movement

C++ 192 22 Updated Dec 14, 2022

Шаблон полнофункционального драйвера и обёртки над ядерным API

C 110 49 Updated Aug 28, 2016

Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.

C++ 309 66 Updated Mar 26, 2024

SoftICE-like kernel debugger for Windows 11

C 929 127 Updated Jul 18, 2023

Basic Windows Kernel Programming

C++ 124 21 Updated May 11, 2020

KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory

C++ 1,994 503 Updated Oct 7, 2024

r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems

C 1 Updated Aug 15, 2018

SDA is a rich cross-platform tool for reverse engineering that focused firstly on analysis of computer games. I'm trying to create a mix of the Ghidra, Cheat Engine and x64dbg. My tool will combine…

C++ 131 14 Updated Dec 28, 2023

2022 Updated Kernelmode-Code

C++ 30 7 Updated Mar 23, 2024

Static Library For Windows Drivers

C++ 30 24 Updated Aug 27, 2024

Inline syscalls made easy for windows on clang

C++ 671 87 Updated Jun 21, 2024

A wrapper library around native windows sytem APIs

C++ 418 85 Updated Feb 2, 2021

A free but powerful Windows kernel research tool.

2,419 570 Updated Oct 14, 2024