This is your work, valued

Samuel Tulach

Elite
@SamuelTulach

Game Security at @Ubisoft

VirusTotalUploader. C# Open-Source Winforms application for uploading files to VirusTotal

1.4k

mutante. Kernel-mode Windows HWID spoofer

628

efi-memory. PoC EFI runtime driver for memory r/w & kdmapper fork

585

memhv. Minimalistic AMD-V/SVM hypervisor with memory introspection capabilities

427

LightHook. Single-header, minimalistic, cross-platform hook library written in pure C

399

negativespoofer. PoC HWID spoofer that runs in EFI

362

rainbow. Hide SMBIOS/disk/NIC serials from EFI bootkit

337

HookGuard. Hooking Windows' exception dispatcher to protect process's PML4

261

tpm-spoofer. Simple proof of concept kernel mode driver hooking tpm.sys dispatch to randomize any public key reads

249

PwnedBoot. Using Windows' own bootloader as a shim to bypass Secure Boot

247

RwxMeme. State of the art DLL injector that took 20 minutes to make

231

SecureFakePkg. Simple EFI runtime driver that hooks GetVariable function and returns data expected by Windows to make it think that it's running with secure boot enabled (faking secure boot)

231

OverlayCord. Simple proof of concept showing how you can use Discord's in-game internal module to draw on top of the game (even if the game is in fullscreen) from an external application without modifying any Discord files or loading its modules.

220

nullmap. Using CVE-2023-21768 to manual map kernel mode driver

201

meme-rw. Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode

161

unxorer. Yet another IDA Pro/Home plugin for deobfuscating stack strings

155

PatchBoot. Guide for patching AMI Aptio V UEFI firmware to circumvent Secure Boot checks

138

BetterTiming. PoC TSC offsetting in KVM

138

SecureHack. Cheat for my own game SecureGame which uses a bootkit to hyperjack Hyper-V in order to access VBS enclave's memory

129

CanetisRadar. Open-source application for detecting sound direction using 7.1 audio device in games

127

eac_cr3_shuffle. C++

107

DirectPageManipulation. A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy

105

voidmap. Using CVE-2021-40449 to manual map kernel mode driver

103

windowhide. Hide external overlay by using SetWindowDisplayAffinity

100

ida-unity-pdb-downloader. Simple IDA Pro plugin to download Unity debug symbols from their symbol server

89

ImGui-AppKit. Project template for single-window GUI apps using Dear ImGui

78

SecureGame. Proof-of-concept game using VBS enclaves to protect itself from cheating

72

MemoryGuard. Experiment with PAGE_GUARD protection to hide memory from other processes

57

Occulto. Proof-of-concept post-build obfuscator for Unity IL2CPP projects

40

InjectMouseInputExample. C/C++ example of InjectMouseInput function

35

winzentool. Port of zentool to Windows

28

GetDeviceInterfacesMemoryLeak. Small memory leak PoC that is happening in IopGetDeviceInterfaces

25

SaberHighlight. Beat Saber mod enabling NVIDIA Highlights functionality

23

vmcheck. C

23

SoundReplacer. BSIPA mod for replacing hit sounds, menu music, click sounds and much more!

21

HitSoundChanger. A plugin for changing hitsounds in Beat Saber

19

OcuFix. Simple mod to automatically disable ASW and change services/runtime priority

19

EasyUefi. Visual Studio template for GNU-EFI

16

disable-memory-compression. Utility for disabling memory compression on Windows

9

InactiveTitlebarPatch. Simple registry patch to turn inactive title bar color dark

8

OneplusDebloat. Remove crappy useless apps in Oxygen OS (both 3rd party and Google)

4

obs-dda. C

4

ByeMouse. C#

4

PowerControl. C#

2

NuGetCheck. C#

1