Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/anylnk/stprocessmonitorbyovd
权限提升漏洞分析漏洞利用渗透测试红队
GitHubanylnk/stprocessmonitorbyovd

STProcessMonitorBYOVD

CVE-2025-70795 / CVE-2026-0828 的 PoC 及更新的驱动程序

查看仓库
50816个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

STProcessMonitorBYOVD

Reference: https://bbs.kafan.cn/thread-2288675-1-1.html

Usage:

  1. Place the vulnerable driver under the same directory of the exe. The version 11.11.4.0 (the older one) is with CVE-2025-70795 / CVE-2026-0828, compatible with the parameter /Kill; The version 11.26.18 (Updated) is compatible with parameter /Terminate.

  2. /Init - Install the driver. /Kill - Use CVE-2025-70795 / CVE-2026-0828 to terminate processes. /Terminate - Use the updated driver to terminate processes. /Uninst - Unload the driver.

Screenshots

Exploit CVE-2025-70795 / CVE-2026-0828 (Please notice that the '/Kill' operate is without any priviledge) 屏幕截图 2026-02-14 200828 屏幕截图 2026-02-14 201224

The updated driver verifys if the control code is from an NT AUTHORITY\SYSTEM process, so we need to get at least Administrator priviledge to use the new driver.

160139uqz99h29c96anwyg 屏幕截图 2026-02-14 201729
下载工具