Skip to content
View xrv3ovl's full-sized avatar

Block or report xrv3ovl

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Tools

84 repositories

Driver Initial Reconnaissance Tool

C 122 31 Updated Dec 26, 2019

Leaked Windows processes handles identification tool

C++ 283 45 Updated Mar 14, 2022

CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers

C 130 40 Updated Sep 5, 2020

Load self-signed drivers without TestSigning or disable DSE. Transferred from https://github.com/DoubleLabyrinth/Windows10-CustomKernelSigners

C++ 716 149 Updated Jan 22, 2020

Binary rewriter for 64-bit PE files.

C++ 70 12 Updated Feb 5, 2024

Cross-platform tool that allows browsing and extracting C and C++ type declarations from PDB files.

Rust 309 23 Updated Feb 9, 2025

Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS.

Rust 331 18 Updated Mar 2, 2025

XDV is disassembler or debugger that works based on the extension plugin.

C++ 54 14 Updated Sep 3, 2019

Shellcodev is a tool designed to help and automate the process of shellcode creation.

C++ 106 30 Updated Oct 11, 2023

Cheat Kernel Injector Support all windows

C++ 88 24 Updated Jan 16, 2023

Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.

C 140 34 Updated Feb 12, 2022

Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.

C++ 316 65 Updated Mar 26, 2024
C 15 10 Updated Dec 16, 2020

A Visual Studio template used to create Cobalt Strike BOFs

C 294 54 Updated Nov 17, 2021

Dump PDB Symbols including support for Bochs Debugging Format (with wine support)

C 15 8 Updated Aug 11, 2023

可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。

C++ 107 36 Updated Sep 1, 2022

基于UC的启发式杀毒引擎[还没做完]

C 33 14 Updated Mar 28, 2021

scan system / process integrity

C++ 294 60 Updated Oct 22, 2024

A tool that allows you to assemble and emulate assembly in multiple archs for learning purposes

C++ 13 4 Updated Mar 15, 2019

内网域渗透小工具

C 723 130 Updated Apr 20, 2021

Pseudo-malicious usermode memory artifact generator kit designed to easily mimic the footprints left by real malware on an infected Windows OS.

C++ 223 54 Updated Mar 18, 2024

A tool that shows detailed information about named pipes in Windows

C# 612 56 Updated Nov 15, 2024

Kernel mode WinDbg extension and PoCs for token privilege investigation.

C# 838 123 Updated Jan 21, 2025

Detect, analyze and uniquely identify crashes in Windows applications

Python 502 89 Updated Feb 20, 2025

A DLL loader with advanced evasive features

C 703 92 Updated Feb 26, 2023

LoadLibrary for offensive operations

C 1,120 207 Updated Oct 22, 2021

now it's updating....

6 4 Updated May 13, 2023

This program can retrieve signature information from PE files which signed by one or more certificates on Windows. Supporting multi-signed (nested) infomation and certificate-chain.

C++ 99 50 Updated Sep 20, 2022

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

C++ 229 27 Updated Sep 26, 2023
Python 138 16 Updated Aug 16, 2024