A circus artist with a visual studio license
WinDbg_Scripts. Useful scripts for WinDbg using the debugger data model
436IoRingReadWritePrimitive. Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2
256PoolViewer. An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.
152CVE-2020-1034. PoC demonstrating the use of cve-2020-1034 for privilege escalation
123SymlinkCallback. A driver that hooks C: volume using symbolic link callback to track all FS access to the volume
108cet-research. A collection of tools, source code, and papers researching Windows' implementation of CET.
94KernelDataStructureFinder. Driver and WinDBG scripts to dump information about all resources and lookaside lists
67IoRing_Demos. A repository for I/O ring demos, use cases and performance testing on Windows
61InformationClasses. Documenting system information classes and their uses
55DpcWait. Driver demonstrating how to register a DPC to asynchronously wait on an object
51MitigationFlagsCliTool. Command like tool to print mitigation flags for running processes in a memory dump
48conference_talks. Slides from various conference talks
38CallbackObjectAnalyzer. Dumps information about all the callback objects found in a dump file and the functions registered for them
38rewolf-wow64ext. Helper library for x86 programs that runs under WOW64 layer on x64 versions of Microsoft Windows operating systems.
7s1dbg. windbg extension that does stuff
7LOLDrivers. Living Off The Land Drivers
5WinObjEx64. Windows Object Explorer 64-bit
2HackSysExtremeVulnerableDriver. HackSys Extreme Vulnerable Windows Driver
1BlogHyperV. Tools made for my Hyper-V blog series @ https://foxhex0ne.blogspot.com/
1ObjectListView. A mirror of the ObjectListView library
1