Stars
Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)
Driver that uses network sockets to communicate with client and read/ write protected process memory.
KSOCKET provides a very basic example how to make a network connections in the Windows Driver by using WSK
Example of hijacking system calls via function pointer tables
Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.
Arbitrary code execution with kernel privileges using CVE-2018-8897.
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
kernel backdoor via registering a malicious SMB handler
awesome game security [Welcome to PR]
A project for allowing EDK-II Development with Visual Studio
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
List of Awesome Advanced Windows Exploitation References
Dark Basic Pro is an open source BASIC programming language for creating Windows applications and games
https://nvd.nist.gov/vuln/detail/CVE-2021-30481
Collection of malware persistence and hunting information. Be a persistent persistence hunter!
📡 PoC auto collect from GitHub.
ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)
🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details, executable file (提权漏洞合集)