Skip to content
View FirstBlue's full-sized avatar

Block or report FirstBlue

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Controlling Windows PP(L)s

C++ 393 63 Updated Jun 9, 2023

The Windows Kernel Programming book samples

C++ 681 133 Updated Sep 25, 2023

KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory

C++ 2,960 627 Updated Mar 21, 2026

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

C++ 2,409 355 Updated Jun 14, 2026

Example applications using the wolfSSL lightweight SSL/TLS library

C 283 200 Updated May 28, 2026

zlib Windows build with Visual Studio.

C 181 54 Updated Feb 27, 2026

openssl-1.1 Windows build with Visual Studio.

C 84 27 Updated Apr 17, 2026

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can be used for stealthy code injection.

C 267 34 Updated Apr 29, 2023

Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)

C++ 19 24 Updated Apr 12, 2020

Load your driver like win32k.sys

C++ 257 70 Updated Aug 20, 2022

KDMAPPER build [1809,1903,1909,2004]

C++ 73 22 Updated Sep 26, 2020

The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).

C++ 289 92 Updated Apr 30, 2026

KSOCKET provides a very basic example how to make a network connections in the Windows Driver by using WSK

C 545 136 Updated Sep 2, 2022

Packet capture on Windows without a kernel driver

C 194 47 Updated Oct 1, 2018

A layer that hide, redirect. forward, re-encrypt internet packet to keep VPN, Proxies and other p2p software hidden from Firewall. Free implementation for HTTP-Tunnel, UDP-Tunnel, port forwarding, …

C++ 188 55 Updated Dec 4, 2018

Detours with just single dependency - NTDLL

C++ 681 123 Updated Nov 25, 2025
C++ 275 54 Updated Jan 14, 2023

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

C++ 727 106 Updated Jul 19, 2023

The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/

C 215 40 Updated Jan 29, 2023

The code is a pingback to the Dark Vortex blog:

C 189 35 Updated Jan 26, 2023

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

C++ 205 41 Updated Aug 2, 2023

SoftICE-like kernel debugger for Windows 11

C 1,045 142 Updated Jul 18, 2023

Shoggoth: Asmjit Based Polymorphic Encryptor

C++ 791 102 Updated Apr 4, 2026

PoC Implementation of a fully dynamic call stack spoofer

C++ 962 110 Updated Jul 20, 2024

Defeating Windows User Account Control

C 7,636 1,423 Updated May 22, 2026

UAC bypass for x64 Windows 7 - 11

C++ 846 161 Updated Feb 2, 2026

Clone of zerosum0x0's Windows Kernel rootkit written in Rust

Rust 8 2 Updated Sep 16, 2022

Run PowerShell with rundll32. Bypass software restrictions.

C# 1,826 256 Updated Mar 17, 2021

Parser to process monitor file formats

Python 165 26 Updated Oct 4, 2025
Next