Skip to content
View xrv3ovl's full-sized avatar

Block or report xrv3ovl

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Tools

84 repositories

Driver Initial Reconnaissance Tool

C 121 34 Updated Dec 26, 2019

Leaked Windows processes handles identification tool

C++ 281 45 Updated Mar 14, 2022

CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers

C 129 40 Updated Sep 5, 2020

Load self-signed drivers without TestSigning or disable DSE. Transferred from https://github.com/DoubleLabyrinth/Windows10-CustomKernelSigners

C++ 712 149 Updated Jan 22, 2020

Binary rewriter for 64-bit PE files.

C++ 67 12 Updated Feb 5, 2024

Cross-platform tool that allows browsing and extracting C and C++ type declarations from PDB files.

Rust 296 19 Updated Aug 26, 2024

Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS.

Rust 331 17 Updated Jan 17, 2025

XDV is disassembler or debugger that works based on the extension plugin.

C++ 54 14 Updated Sep 3, 2019

Shellcodev is a tool designed to help and automate the process of shellcode creation.

C++ 104 28 Updated Oct 11, 2023

Cheat Kernel Injector Support all windows

C++ 90 23 Updated Jan 16, 2023

Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.

C 139 33 Updated Feb 12, 2022

Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.

C++ 312 66 Updated Mar 26, 2024
C 15 10 Updated Dec 16, 2020

A Visual Studio template used to create Cobalt Strike BOFs

C 288 54 Updated Nov 17, 2021

Dump PDB Symbols including support for Bochs Debugging Format (with wine support)

C 15 8 Updated Aug 11, 2023

可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。

C++ 107 36 Updated Sep 1, 2022

基于UC的启发式杀毒引擎[还没做完]

C 31 11 Updated Mar 28, 2021

scan system / process integrity

C++ 283 57 Updated Oct 22, 2024

A tool that allows you to assemble and emulate assembly in multiple archs for learning purposes

C++ 13 4 Updated Mar 15, 2019

内网域渗透小工具

C 722 130 Updated Apr 20, 2021

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

C++ 223 54 Updated Mar 18, 2024

A tool that shows detailed information about named pipes in Windows

C# 579 50 Updated Nov 15, 2024

Kernel mode WinDbg extension and PoCs for token privilege investigation.

C# 828 124 Updated Jan 14, 2025

Detect, analyze and uniquely identify crashes in Windows applications

Python 502 90 Updated Jul 9, 2024

A DLL loader with advanced evasive features

C 687 91 Updated Feb 26, 2023

LoadLibrary for offensive operations

C 1,110 206 Updated Oct 22, 2021

now it's updating....

5 3 Updated May 13, 2023

This program can retrieve signature information from PE files which signed by one or more certificates on Windows. Supporting multi-signed (nested) infomation and certificate-chain.

C++ 99 50 Updated Sep 20, 2022

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

C++ 227 25 Updated Sep 26, 2023
Python 131 16 Updated Aug 16, 2024