Skip to content
View FirstBlue's full-sized avatar

Block or report FirstBlue

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Controlling Windows PP(L)s

C++ 283 51 Updated Jun 9, 2023

The Windows Kernel Programming book samples

C++ 618 128 Updated Sep 25, 2023

KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory

C++ 2,119 521 Updated Feb 9, 2025

Nidhogg is an all-in-one simple to use windows kernel rootkit.

C++ 1,875 281 Updated Oct 3, 2024

Example applications using the wolfSSL lightweight SSL/TLS library

C 259 177 Updated Feb 6, 2025

zlib Windows build with Visual Studio.

C 168 49 Updated Mar 25, 2024

openssl-1.1 Windows build with Visual Studio.

C 78 26 Updated Dec 22, 2023

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can be used for stealthy code injection.

C 238 33 Updated Apr 29, 2023

Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)

C++ 20 26 Updated Apr 12, 2020

Load your driver like win32k.sys

C++ 251 72 Updated Aug 20, 2022

KDMAPPER build [1809,1903,1909,2004]

C++ 70 20 Updated Sep 26, 2020

The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).

C++ 241 83 Updated Jan 27, 2025

KSOCKET provides a very basic example how to make a network connections in the Windows Driver by using WSK

C 486 130 Updated Sep 2, 2022

Packet capture on Windows without a kernel driver

C 182 46 Updated Oct 1, 2018

A layer that hide, redirect. forward, re-encrypt internet packet to keep VPN, Proxies and other p2p software hidden from Firewall. Free implementation for HTTP-Tunnel, UDP-Tunnel, port forwarding, …

C++ 181 58 Updated Dec 4, 2018

Detours with just single dependency - NTDLL

C++ 618 122 Updated Aug 24, 2022
C++ 231 51 Updated Jan 14, 2023

HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.

C++ 648 100 Updated Jul 19, 2023

The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/

C 175 35 Updated Jan 29, 2023

The code is a pingback to the Dark Vortex blog:

C 170 32 Updated Jan 26, 2023

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

C++ 184 38 Updated Aug 2, 2023

SoftICE-like kernel debugger for Windows 11

C 951 128 Updated Jul 18, 2023

Shoggoth: Asmjit Based Polymorphic Encryptor

C++ 701 90 Updated Apr 10, 2024

PoC Implementation of a fully dynamic call stack spoofer

C++ 738 96 Updated Jul 20, 2024

Defeating Windows User Account Control

C 6,558 1,332 Updated Feb 7, 2025

UAC bypass for x64 Windows 7 - 11

C++ 793 153 Updated Jul 27, 2022

Clone of zerosum0x0's Windows Kernel rootkit written in Rust

Rust 5 2 Updated Sep 16, 2022

Run PowerShell with rundll32. Bypass software restrictions.

C# 1,788 254 Updated Mar 17, 2021

Parser to process monitor file formats

Python 137 23 Updated Apr 6, 2023
Next