Repository navigation
ntoskrnl
- Website
- Wikipedia
Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.
Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS.
The history of Windows Internals via symbols.
Enumerate user mode shared memory mappings on Windows.
Kernel Level NMI Callback Blocker
Windows kernel debugger for Linux hosts running Windows under KVM/QEMU
Analysis of the vulnerability
Kernel Mode DLL Manual Mapper
A fast method to intercept syscalls from any user-mode process using InstrumentationCallback and detect any process using InstrumentationCallback.
EPROCESS Unlinking example in "C" using DKOM Manipulation
PsLoadedModuleList Unlinking through DKOM Manipulation
All undocumented ntoskrnl structs crawled from vergiliusproject.com