Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
KernelFlirt — Windows kernel-level debugger with OllyDbg/IDA-style UI, software and hardware breakpoints, PDB symbols, decompiler, and 17 plugins for reverse engineering and malware analysis in VMs. | Kitploit
Tools/GitHubGitHub/akatorich/kernelflirt
Static AnalysisDynamic Analysis (Sandboxing)Memory ForensicsReverse EngineeringDebuggersMalware AnalysisUtilities & FrameworksBinary AnalysisAI-Assisted ReversingAnti-BotAI SecurityBinary Exploitation
32574 months agoReviewed by Kitploit
GitHubakatorich/kernelflirt

KernelFlirt

Windows kernel-level debugger with OllyDbg/IDA-style UI, software and hardware breakpoints, PDB symbols, decompiler, and 17 plugins for reverse engineering and malware analysis in VMs.

View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

KernelFlirt

Windows kernel-level debugger with an OllyDbg/IDA Pro-style interface. Designed for security research, reverse engineering, and malware analysis in VM environments (VMware).

KernelFlirt

Architecture

  Host machine                           VM (Windows 10, testsigning)
┌──────────────────┐    TCP:31337    ┌──────────────────┐     IOCTL      ┌──────────────────┐
│  KernelFlirt UI  │◄───────────────►│   KfRelay.exe    │◄──────────────►│ KernelFlirt.sys  │
│  (WPF / .NET 9)  │  CMD+DBG ch.    │   (TCP proxy)    │  DeviceIoCtl   │ (WDM Driver)     │
└──────────────────┘                 └──────────────────┘                └──────────────────┘
                                     ┌──────────────────┐  SCM API
                                     │  KfLoader.exe    │──────────────────────┘
                                     │  (C / Console)   │  load / unload / status
                                     └──────────────────┘
ComponentLanguageDescription
KernelFlirt.UIC# / WPFDebugger interface (runs on host)
KernelFlirt.sysC / WDMKernel driver — memory, breakpoints, KdTrap inline hook
KfRelay.exeCTCP relay on VM, proxies IOCTLs over network
KfLoader.exeCCLI to load/unload the driver via SCM
KfConsole.exeC# / .NET 9Console debugger — WinDbg/x64dbg-style REPL over the same driver
KernelFlirt.SDKC# / .NET 9Plugin SDK — full debugger API for extensions

Quick Start

:: VM — load driver and start relay
KfLoader.exe load
KfRelay.exe

:: Host — launch the UI and connect
KernelFlirt.exe → Connect → VM IP
  1. File → Open — browse VM filesystem, select EXE/SYS
  2. Process created suspended, entry point BP set automatically
  3. F9 — run to entry point, symbols and modules load
  4. Set breakpoints, step through code, inspect memory and registers

Kernel driver debugging: open Kernel Modules tab, find your driver, set breakpoints on any function — user-mode and kernel-mode.

Console Front-End (KfConsole)

Don't need the WPF UI? KfConsole.exe (in bin\Console\) is a WinDbg/x64dbg-style REPL over the same driver and relay.

kf> connect 10.100.102.6:31337
✓ connected (10.100.102.6:31337), driver v0x10000

kf*> open C:\Temp\target.exe
✓ created PID=8424 TID=10136 ImageBase=00007FF7`2EA10000 (x64)
symbols: 3/4 modules loaded

kf(8424:10136/x64/brk)> bp ntdll!NtCreateFile if rcx!=0
✓ bp [1] 00007FFF`BBF8E030  ntdll!NtCreateFile  if rcx!=0

kf(8424:10136/x64/brk)> g
*** BP at 00007FFF`BBF8E030  ntdll!NtCreateFile

kf(8424:10136/x64/brk)> u rip 5
►  00007FFF`BBF8E030  4c 8b d1  mov r10, rcx  ntdll!NtCreateFile

Highlights: x64 + WoW64 (x86) targets, PDB symbol resolution via Microsoft Symbol Server, expression evaluator (rsp+8, [rsp], module!func), conditional breakpoints, Step Into / Step Over / Step Out, anti-debug primitives, ANSI-colored output, readline with persistent history.

Full command reference: docs/cli.md

Features

Debugging

  • Software breakpoints (INT3), hardware breakpoints (DR0-DR3), memory breakpoints (PAGE_GUARD)
  • Hardware watchpoints — write and read/write data (1/2/4/8 bytes)
  • Conditional and logging breakpoints
  • Step into (F7), step over (F8), step out (Ctrl+F9), run to cursor (F4)
  • Register editing — modify any GPR, RIP, RFLAGS, DR0-7
  • Inline assembler, NOP patching, patch tracking with undo

Analysis

  • Hex dump with binary pattern search (?? wildcards)
  • String search (ASCII/Unicode) across all modules
  • Module, thread, call stack, SEH chain enumeration
  • Imports, exports, sections, functions lists
  • Memory allocation, protection changes, snapshot & diff
  • RetDec decompiler with theme-aware C syntax highlighting
  • IDA-style navigation bar — color-coded section map with RIP/breakpoint/bookmark markers
  • PDB symbol resolution via Microsoft Symbol Server
  • User-defined function naming with RegisterFunction

Themes

9 built-in themes (default-dark, x64dbg, monokai, ollydbg, ollydbg-light, ida-pro, dracula, long_night, sakura) with runtime switching and 100+ customizable color keys.

Plugins (17)

Reverse Engineering

PluginDescription
Graph ViewIDA-style CFG with block coloring, collapse/expand, function navigation
XrefsCross-references — find all callers/references to any address
FLIRT SignaturesFunction recognition by byte patterns (.pat + built-in MSVC CRT)
Signature DetectorPEiD-compatible packer/compiler detection (4445 signatures)
PE RebuilderPE dumper with IAT reconstruction (Scylla-style)
String DecryptorAutomated string decryption
VulnHunterDangerous API usage scanner

Dynamic Analysis

PluginDescription
API MonitorReal-time API interception with parameter logging
Network MonitorNetwork traffic capture (send/recv/connect) with CSV export
Memory ScannerValue scanning with subsequent filtering
Themida UnpackerAutomated Themida/WinLicense unpacker

Automation & AI

PluginDescription
C# ScriptingRoslyn REPL with full debugger API, syntax highlighting, persistent state
AI AssistantReverse engineering assistant (OpenAI-compatible) with 65+ debugger tools
MCP ServerModel Context Protocol — connect AI clients (Claude Code, Cursor) to debugger
Session ManagerSave/load session (breakpoints, comments, function names) with ASLR rebase
Bookmarks/NotesAddress bookmarks with annotations, persisted between sessions
Anti-Debug BypassAutomatic PEB/DebugPort/ThreadHide/HeapFlags patching

All plugins share a common SDK with access to memory, breakpoints, symbols, UI, events, execution control, and cross-plugin communication.

Keyboard Shortcuts

KeyAction
F2Toggle breakpoint
F4Run to cursor
F5 / F9Continue / Run
F7Step into
F8Step over
Ctrl+F9Step out
F12Pause
SpaceInline assembler
Ctrl+GGo to address
Ctrl+FBinary search
F11Fullscreen
Shift+F5Run script

Documentation

DocumentENRU
SDK & Plugin DevelopmentSDK-en.mdSDK-ru.md
C# Scripting Referencescripting-reference-en.mdscripting-reference-ru.md
CLI (KfConsole)cli.md—
ChangelogCHANGELOG.md

SDK (~55 pages)

Complete guide to building KernelFlirt plugins: project setup, all API interfaces with full parameter descriptions, data models, UI development (WPF/theming), events, threading, cross-plugin communication, persistence, anti-debug API, 4 complete example plugins, best practices.

Scripting Reference (~30 pages)

C# REPL scripting guide: all shortcuts and API methods with parameters, 12 data models, 18+ real-world recipes (PE analysis, string decryption, IAT reconstruction, unpacker scripting, memory scanning, API tracing), tips & pitfalls.

Building

Requirements: Visual Studio 2022 (C++), WDK 10.0.26100.0+, .NET 9 SDK, Windows 10/11 x64

Download Tool