
antidbg
A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering

A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering

Winstrument is a framework of modular scripts to aid in instrumenting Windows software using Frida for reverse engineering and attack surface…

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on…

Drltrace is a library calls tracer for Windows and Linux applications.

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

Proof-of-concept that exploits a Kaspersky driver vulnerability to leak kernel pointers and bypass KASLR on Windows, enabling kernel exploit chain…

Simple C program to quickly deobfuscate windows executables protected with Arxan.

idenLib - Library Function Identification [This project is not maintained anymore]

IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix…

A critical local privilege escalation vulnerability has been discovered in Acer NitroSense software (PSAdminAgent.exe). The vulnerability allows any…

Windows tool for dumping malware PE files from memory back to disk for analysis.

Curated collection of P/Invoke definitions from pinvoke.net with Microsoft documentation links, enabling quick Windows API prototyping for security…

Windows kernel driver experiment based on KasperskyHook that uses direct syscalls for interprocess memory copying, with support for unloading the…

An Interactive Binary Patching Plugin for IDA Pro

Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.

pefile is a Python module to read and work with PE (Portable Executable) files

Local PE injection technique using hardware breakpoints and vectored exception handling to manipulate DLL loading and execute arbitrary payloads, as…
