ReverseKit. x64 Dynamic Reverse Engineering Toolkit
771mhydeath. Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.
410Ophion. Stealth-focused Intel VT-x hypervisor (EAC/BE/ACs/AVs).
383GDRVLoader. Unsigned driver loader using CVE-2018-19320
365ZeroHVCI. Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers.
291NVDrv. Abusing nvidia driver (nvoclock.sys) for physical/virtual memory and control register manipulation.
287ZeroThreadKernel. Recursive and arbitrary code execution at kernel-level without a system thread creation
158Demystifying-PatchGuard. Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unauthorized modifications to the Windows kernel. The analysis is done through practical engineering, with a focus on understanding PatchGuard's inner workings.
136BusterCall. "Bypassing" HVCI via donor PFN swaps to modify read-only code pages. Call chained kernel functions (kCET and SLAT support), and more.
129Reversing-a-signed-driver. Reverse Engineering a signed kernel driver packed and virtualized with VMProtect 3.6
108NTMemory. Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.
89GDRVLib. Virtual and physical memory hacking library using gigabyte vulnerable driver
70AsusDrv. Abusing AsusBiosIoDrv64.sys to gain kernel and process physical/virtual memory access.
28x670e-tomahawk-anticheat-update. Reverse of MSI's MAG X670E TOMAHAWK WIFI bios v1KB (2026-03-20) which claims "Implemented the anti-cheat mechanism" in the release notes.
16KernelSnippets. C
15hv. C
11miVault. simple program for xorcrypting and storing files into media files like audios, images and videos while maintaining integrity.
10xSIMD. Cross-platform SIMD assembler that emits unified vector instructions to native x86, ARM, and RISC-V machine code.
8memoryPy. Python
6WRK. The Windows Research Kernel (WRK)
4ia32-doc. IA32-doc is a project which aims to put as many definitions from the Intel Manual into machine-processable format as possible
1