Highlights
- Pro
Stars
Load self-signed drivers without TestSigning or disable DSE. Transferred from https://github.com/DoubleLabyrinth/Windows10-CustomKernelSigners
Activation cache poisoning to elevate from medium to high integrity (CVE-2024-6769)
📝 File hashing and checking shell extension
A back-tester for testing stock trading strategies on historical data
Admin to Kernel code execution using the KSecDD driver
Single header version of System Informer's phnt library.
Diff and display virtual machine snapshots
Execute PowerShell code at the antimalware-light protection level.
Dump the memory of any PPL with a Userland exploit chain
PoC capable of detecting manual syscalls from usermode.
woftool is a proof-of-concept utility for creating WOF-compressed files
A collection of tools, source code, and papers researching Windows' implementation of CET.