KiFilterFiberContext
KiFilterFiberContext
VMP3-Disasm
Experimental disassembler for x86 binaries virtualized by VMProtect 3
warbird-hook
Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard
BadlionLogger
kernel driver used to monitor the activity of BadlionAnticheat.sys by patching its IAT
GD-Editor-Leak
reverse engineered structures and editor code needed to reimplement the editor in the 2019 Geometry Dash 2.2 leaks
microsoft-warbird
Reimplementation of Microsoft's Warbird obuscator
warbird-obfuscator
Integration of Microsoft Warbird with the MSVC compiler
windows-software-policy
Research on obfuscated licensing APIs / CLIP service in the Windows kernel