anycall. x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration
412evil-mhyprot-cli. A PoC for Mhyprot2.sys vulnerable driver that allowing read/write memory in kernel/user via unprivileged user process.
357PageTableInjection. Code Injection, Inject malicious payload via pagetables pml4.
244anymapper. x64 Windows kernel driver mapper, inject unsigned driver using anycall
218NoPatchGuardCallback. x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code
208CVE-2022-42046. CVE-2022-42046 Proof of Concept of wfshbr64.sys local privilege escalation via DKOM
161MsIoExploit. Exploit MsIo vulnerable driver
143libmhyprot. A static library, wrapper for mhyprot vulnerable driver, execute exploits and tests
132NtSymbol. Resolve DOS MZ executable symbols at runtime
96Van1338. A journal for $6,000 Riot Vanguard bounty.
71razy_importer. Rust implementation of lazy_importer
61anyvtop. x64 Windows implementation of virtual-address to physical-address translation
54kernel_callbacks. Bypasses for Windows kernel callbacks PatchGuard protection
44kdump. A kernel module dumper for Windows x64 using mhyprot vulnerable driver
36EvilHooker. Function hooks in Windows NT Kernel
26detect-anyrun. ANY.RUN sandbox detection collection
25anyelevate. x64 Windows privilege elevation using anycall
22ProcessVmAccess. Two PoC of accessing process virtual memory via NT Kernel
21CiGetCertPublisherName. An example code of CiGetCertPublisherName
15EQU8-PoC. A proof-of-concept to abuse EQU8 anti-cheat kernel driver
15Process-Dumper. Memory Dumper For Win10 x64 Processes
15ZemanaLPE. A proof-of-concept of local privilege escalation by exploiting Zemana AntiMalware/AntiLogger
14CVE-2017-9769. A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.
13libinject. A dll injector static library for Win x64 processes with handle elevation supported
12rust-vcpu. Virtual CPU with its own architecture, written in Rust.
9CSharp-AES-Algorithm. The AES algorithm implementation with C#
8jekyll-twitter-theme. A twitter theme for Jekyll.
6hcaptcha-module. hCaptcha integration with Nuxt.js
6hhide. Windows x86-64 process protection w/ hiding handle via ObRegisterCallbacks
5mold. Mold: A Modern Linker for Windows 🦠
4kdmapper. KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory
4IDARustCargo. Python
4UnityMonoInject. Inject arbitrary managed code to the Unity games
3lazy_importer. library for importing functions from dlls in a hidden, reverse engineer unfriendly way
3kmp. C++
3kernel32-imports. import list of kernel32.dll in Win10 1909 18363.1139
3ExploitCapcom. This is a standalone exploit for a vulnerable feature in Capcom.sys
3CheckPagingDrv. Read CR0 and Check Paging Flag
3ntstatus. NTSTATUS bindings for Rust
2vgrl1337. Vanguard vgrl.dll ordinal 1337 is a mystery
2OverlayD3D9. Simple overlay using D3D9
2notify-icon-rs. A safe, ergonomic Rust wrapper around the Windows Shell_NotifyIcon API for managing system tray icons on Windows platforms
2libconsole. ✨ Beautiful printouts in Python
2SHA256-Algorithm-CSharp. SHA256 Algorithm Implementation Using C#
2goblin-experimental. (Experimental) An impish, cross-platform binary parsing crate, written in Rust
1winapi-rs. Rust bindings to Windows API
1PSVSEnv. Fork of PSVSEnv
1scroll. Scroll - making scrolling through buffers fun since 2016
1windows-service-rs. Windows services in Rust
1goblin. An impish, cross-platform binary parsing crate, written in Rust
1transacted_hollowing. Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging
1twitcasting-py. An unofficial python module for wrapping TwitCasting common APIs
1nest-google-recaptcha. Google recaptcha module for nestjs
1reactos. A free Windows-compatible Operating System
1