
Driver-HideKernelThread-IoCancelIrp
Windows kernel driver technique that hides kernel threads by abusing IoCancelIrp and IRP cancel routines, with detection methods for identifying…
binary-analysisdefensive-toolsmalware-analysis+1

Windows kernel driver technique that hides kernel threads by abusing IoCancelIrp and IRP cancel routines, with detection methods for identifying…

Win32 and Kernel abusing techniques for pentesters

exp for CVE-2019-0887

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

This is a keylogger that collects all the data and e-mail it in a set time with system information which includes device S/N and hardware specs,…