-
NtWarden Public
Forked from mrT4ntr4/NtWardenWindows Analysis and Research Toolkit
C++ MIT License UpdatedApr 10, 2026 -
lsawhisper-bof Public
Forked from dazzyddos/lsawhisper-bofA Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without touching LSASS process memory.
C UpdatedFeb 21, 2026 -
TokenTheft_PoC Public
Forked from classic130/TokenTheft_PoCA Proof-of-Concept (POC) demonstration of Windows token impersonation techniques for educational and security research purposes.
-
NSI-MAC-Spoofing Public
Forked from MicrosoftMacroAssembler/NSI-MAC-SpoofingMAC address spoofer using NSI completion routine hooking
C++ UpdatedJan 28, 2026 -
Thread-Priority-Guard Public
Forked from MicrosoftMacroAssembler/Thread-Priority-GuardThread priority based throttling system thats budget-based
C++ UpdatedJan 28, 2026 -
Minimalist-Driver Public
Forked from MicrosoftMacroAssembler/Minimalist-DriverMinimalist was a spoofing driver using a Registry Callback inspired by me
C++ UpdatedJan 28, 2026 -
Win32kHooker Public
Forked from GetRektBoy724/Win32kHooker.data ptr swapper for newer win32k versions. (Supports Windows 11)
C++ UpdatedJan 19, 2026 -
AsusDrv Public
Forked from zer0condition/AsusDrvAbusing AsusBiosIoDrv64.sys to gain kernel and process physical/virtual memory access.
C++ UpdatedJan 17, 2026 -
CoreLib Public
Forked from freezerdev/CoreLibA cross-platform library of very useful functions and classes
C++ UpdatedJan 5, 2026 -
DbgNexum Public
Forked from dis0rder0x00/DbgNexumShellcode injection using the Windows Debugging API
C MIT License UpdatedJan 4, 2026 -
VPGATHER Public
Forked from Peribunt/VPGATHERUsing the peculiar behaviour of the VPGATHER instructions to determine if an address will fault before it is truly accessed. All done in user-mode.
C++ UpdatedDec 30, 2025 -
Nemesis Public
Forked from DaedalusFrame/NemesisWindows kernel driver that detects hypervisors by probing SIDT/LIDT edge cases, paging/TLB behaviors, privilege transitions, and timing executed inside a controlled safety-net environment.
C++ UpdatedDec 17, 2025 -
Killer Public
Forked from Nekr0w/killerNon HVCI Block listed - Microsoft signed driver exploited to kill AV/EDR's processes
C UpdatedDec 14, 2025 -
VectoredOverloading Public
Forked from CheckPointSW/VectoredOverloadingC++ MIT License UpdatedDec 11, 2025 -
droneengage_communication Public
Forked from DroneEngage/droneengage_communicationMain DroneEngage Unit Component
C++ UpdatedDec 4, 2025 -
PrivKit Public
Forked from mertdas/PrivKitPrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.
C GNU General Public License v3.0 UpdatedNov 29, 2025 -
HerculesAC Public
Forked from un4ckn0wl3z/HerculesACHercules Anti-Cheat | Homemade Usermode and Kernelmode Anti-Cheat
C UpdatedNov 24, 2025 -
awesome-llvm-security Public
Forked from gmh5225/awesome-llvm-securityawesome llvm security [Welcome to PR]
MIT License UpdatedNov 24, 2025 -
KeyboardKit Public
Forked from wesmar/KeyboardKitWindows Kernel-Mode Keylogger - Educational rootkit driver intercepting keyboard IRPs for UDP logging. Demonstrates stealth persistence, privilege escalation & IRP hooking for offensive security re…
C++ Other UpdatedNov 21, 2025 -
KernelResearchKit Public
Forked from wesmar/KernelResearchKitWindows 11 kernel research framework demonstrating DSE bypass on Windows 11 25H2 through boot-time execution. Loads unsigned drivers by surgically patching SeCiCallbacks via native subsystem. Inclu…
C++ UpdatedNov 21, 2025 -
Hermes2 Public
Forked from Skeletal-Group/HermesFast covert timing channel communication for inter-process and inter-processor communication on Windows systems.
C++ UpdatedNov 15, 2025 -
KDemu Public
Forked from ShallowFeather/KDemuA Windows Kernel Driver Emulator base on Unicorn, Kernel Memory Dump and some of native environment
C++ UpdatedNov 4, 2025 -
WinArk Public
Forked from BeneficialCode/WinArkWindows Anti-Rootkit Tool
C++ MIT License UpdatedNov 4, 2025 -
RedEdr Public
Forked from dobin/RedEdrCollect Windows telemetry for Maldev
C++ GNU General Public License v3.0 UpdatedNov 2, 2025 -
i386-emulator Public
Forked from un4ckn0wl3z/i386-emulatorAn experimental i386 CPU emulator designed to explore how a processor fetches, decodes, and executes instructions in real mode.
C UpdatedOct 18, 2025 -
EAC-CR3-BYPASS Public
Forked from kprprivate/EAC-CR3-BYPASSA simple UM + KM example of how to bypass EAC CR3
C UpdatedOct 13, 2025 -
AsmLdr Public
Forked from 0xNinjaCyclone/AsmLdrDynamic shellcode loader with sophisticated evasion capabilities
Assembly MIT License UpdatedOct 1, 2025 -
kurasagi Public
Forked from NeoMaster831/kurasagiWindows 11 24H2 Runtime PatchGuard Bypass
C++ Apache License 2.0 UpdatedAug 13, 2025 -
-
vmprotectunpacker Public
Forked from sudha2323/vmprotectunpackerA custom tool to unpack VMProtect-obfuscated executables and restore the original binary
C++ UpdatedJul 30, 2025