PoC EFI runtime driver for memory r/w & kdmapper fork
Updated 2025-11-24 15:41:25 +08:00
The research UEFI hypervisor that supports booting an operating system.
Updated 2025-11-24 15:41:04 +08:00
abusing signed pdfwkrnl.sys for kernel function calling from usermode.
Updated 2025-11-24 15:40:28 +08:00
An Unsigned Driver Mapper for Windows 10 22H2 -> Windows 11 23H2 that uses PdFwKrnl to exploit the Read/Write IOCTL Calls to disable DSE & PG to map the unsigned driver.
Updated 2025-11-24 15:40:09 +08:00
Stack integrity verification to Detect SleepMask or CallStack Spoofer
Updated 2025-11-24 15:39:44 +08:00
Windows 应急响应手册
Updated 2025-11-24 15:36:57 +08:00
Linux 应急响应手册
Updated 2025-11-24 15:36:32 +08:00
戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
Updated 2025-11-24 09:44:02 +08:00
A simple, open source bilingual translation extension & Greasemonkey script (一个简约、开源的 双语对照翻译扩展 & 油猴脚本)
Updated 2025-11-24 09:43:51 +08:00
Upgrade all the things
Updated 2025-11-24 09:43:35 +08:00
🔥小巧、美观的桌面快速启动工具 Small, beautiful desktop quickstart management tool with integrated Everything search
Updated 2025-11-24 09:42:51 +08:00
Go programming language with Windows 7/Windows Server 2008 R2 support* plus classic `go get` behaviour
Updated 2025-11-24 09:42:43 +08:00
KVC enables unsigned driver loading via DSE bypass (g_CiOptions patch/skci.dll hijack) and PP/PPL manipulation for LSASS memory dumping on modern Windows with HVCI/VBS.
bypass-dse-load-unsigned-driver-windows11
disable-windows-defender-tamper-protection
driver-signature-enforcement-bypass-hvci-windows
dump-lsass-memory-protected-process-light
kernel-driver-stealth-loading
protected-process-light-ppl-wintcb-bypass
secureboot-disable-unsigned-driver-load
unprotect-process-ppl-wintcb
windows-watermark-removal-tool
Updated 2025-11-24 09:38:16 +08:00