Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.
翻译 - 用于自动简化 Windows 内核反编译的 Hex-Rays 微码插件。
Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS.
The history of Windows Internals via symbols.
翻译 - Windows Internals通过符号的历史记录。
Enumerate user mode shared memory mappings on Windows.
Kernel Level NMI Callback Blocker
Windows kernel debugger for Linux hosts running Windows under KVM/QEMU
Collect various versions of ntoskrnl files
Analysis of the vulnerability
Kernel Mode DLL Manual Mapper
A fast method to intercept syscalls from any user-mode process using InstrumentationCallback and detect any process using InstrumentationCallback.
Game Engine from an ADHDer that will never be finished.
EPROCESS Unlinking example in "C" using DKOM Manipulation
PsLoadedModuleList Unlinking through DKOM Manipulation
All undocumented ntoskrnl structs crawled from vergiliusproject.com