
antidbg
A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering

A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Drltrace is a library calls tracer for Windows and Linux applications.

Proof-of-concept that exploits a Kaspersky driver vulnerability to leak kernel pointers and bypass KASLR on Windows, enabling kernel exploit chain…

Simple C program to quickly deobfuscate windows executables protected with Arxan.

idenLib - Library Function Identification [This project is not maintained anymore]

TrueType and OpenType font fuzzing toolset

IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…

Research and proof-of-concept for module stomping, a technique to hide malicious code in legitimate Windows modules, with documentation and…

A critical local privilege escalation vulnerability has been discovered in Acer NitroSense software (PSAdminAgent.exe). The vulnerability allows any…

Proof-of-concept exploit for CVE-2020-14955 targeting a kernel driver IOCTL vulnerability in Jiangmin Antivirus 16.0.13.129 on Windows 7 x32.

Windows tool for dumping malware PE files from memory back to disk for analysis.

Windows kernel driver technique that hides kernel threads by abusing IoCancelIrp and IRP cancel routines, with detection methods for identifying…

An Interactive Binary Patching Plugin for IDA Pro

pefile is a Python module to read and work with PE (Portable Executable) files


Windows BYOVD research on DCRCVDrv.sys and Alinubx.sys, reverse engineering their kernel primitives, IOCTL surfaces, and detection opportunities.