Michael B.
Michael B.
CallMon
CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers
ALPC-Example
An example of a client and server using Windows' ALPC functions to send and receive data.
CVE-2018-16712
PoC Code for CVE-2018-16712 (exploit by MmMapIoSpace)
CVE-Stockpile
Master list of all my vulnerability discoveries. Mostly 3rd party kernel drivers.
DynamicKernelShellcode
An example of how x64 kernel shellcode can dynamically find and use APIs
WhoCalls_C
WhoCalls can query a directory of files, find the binaries, and search for a user specified Win API import. It and works with both 32-bit (PE) and 64-bit (PE32+) file formats (.exe, .dll, .sys)
WarbirdExamples
An example of how to use Microsoft Windows Warbird technology