
FakeMBR
TDL4 style rootkit to spoof read/write requests to master boot record
binary-analysisexploitationmalware-analysis+2
135

TDL4 style rootkit to spoof read/write requests to master boot record

Proof-of-concept that exploits a Kaspersky driver vulnerability to leak kernel pointers and bypass KASLR on Windows, enabling kernel exploit chain…

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

PoCs for Kernelmode rootkit techniques research.

Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…