Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View Xacone's full-sized avatar
🧊
On the rockz
🧊
On the rockz

Organizations

@ESIR2-PROJET-KEOLIS @TPs-ESIR-S9

Block or report Xacone

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A small library to modify all page-table levels of all processes from user space for x86_64 and ARMv8.

C 277 70 Updated Apr 24, 2025

Browse Page Tables on Windows (Page Table Viewer)

C# 231 45 Updated Apr 2, 2022

RpcView is a free tool to explore and decompile Microsoft RPC interfaces

C++ 1,030 256 Updated Sep 24, 2023

AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

Python 4,653 489 Updated Dec 11, 2025

EDK II

C 5,659 2,970 Updated Dec 19, 2025

A .net OLE/COM viewer and inspector to merge functionality of OleView and Test Container

C# 1,351 195 Updated Dec 9, 2024

Find out how to bypass HVCI (or not). My own research on Microsoft Warbird (specifically in clipsp.sys)

80 4 Updated Oct 26, 2025

WNF Utilities 4 Newbies (WNFUN)

Python 98 16 Updated Dec 6, 2018

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

C 310 65 Updated Apr 16, 2024

PDB file inspection tool

Pascal 116 4 Updated Nov 21, 2025

Python scripts for reverse engineering.

Python 186 52 Updated May 7, 2021

Research on Windows Kernel Executive Callback Objects

C 312 70 Updated Feb 22, 2020

FindFunc is an IDA Pro plugin to find code functions that contain a certain assembly or byte pattern, reference a certain name or string, or conform to various other constraints.

Python 353 33 Updated Nov 17, 2025

Simple x86-64 VT-x Hypervisor with EPT Hooking

C 939 163 Updated Apr 24, 2023

Harness to issue Virtual Secure Mode (VSM) "secure calls" from VTL 0 to VTL 1

C++ 68 6 Updated Sep 8, 2025

Intel VT-x based hypervisor aiming to provide a thin VM-exit filtering platform on Windows.

C++ 1,707 428 Updated Nov 24, 2023

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Shell 829 96 Updated Mar 5, 2025

A Linux Auditd rule set mapped to MITRE's Attack Framework

818 131 Updated Jul 8, 2020

Transform Linux Audit logs for SIEM usage

Rust 805 62 Updated Dec 18, 2025

Guest services for eryph

C# 13 Updated Oct 17, 2025

Virtual Trust Level (VTL 1) secure call tracing

C++ 83 11 Updated Aug 29, 2025

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

C++ 229 26 Updated Nov 4, 2025

Demonstrate calling a kernel function and handle process creation callback against HVCI

C++ 79 14 Updated Dec 21, 2022

A simple hypervisor demonstrating the use of the Intel VT-rp (redirect protection) technology.

Rust 111 10 Updated Mar 28, 2024

SSDE is a collection of utilities that help in having Windows load your custom signed kernel drivers when Secure Boot is on and you own the system's platform key, instead of using test mode.

C++ 250 44 Updated Aug 27, 2021

Monitoring and controlling kernel API calls with stealth hook using EPT

C++ 1,331 340 Updated Jan 22, 2022

Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls

Rust 206 26 Updated Aug 31, 2025

MemProcFS

C 3,926 496 Updated Dec 3, 2025

NovaHypervisor is a defensive x64 Intel host based hypervisor. The goal of this project is to protect against kernel based attacks (either via Bring Your Own Vulnerable Driver (BYOVD) or other mean…

C++ 237 22 Updated Oct 6, 2025

Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unauthorized modifications to the Windows kernel. The analysis is…

C 130 28 Updated Apr 26, 2023
Next