0xJs/BYOVD_read_write_primitive
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
Repository profile
Correlating kernel notifications with the lack of ETW events to detect ETW Patching
Repository updates
Get generated 0xjbb/EyYoEtwWhereYouAt development summaries by email, or follow the weekly and monthly RSS feeds.
Sign in to subscribe by email. RSS feeds are public.
Sign in to subscribeTracked growth, recent movement, and commit velocity from stored repository snapshots.
Latest capture 2026-06-24 13:00
1 capture since 2026-06-24
Stars from baseline 0
All tracked data
Frameworks, package managers, ecosystems, and dependency manifests found during catalog scans.
Scanned 2026-06-24 13:00
CMakeLists.txt
c-cpp ecosystem,
0 dependencies
Test/CMakeLists.txt
c-cpp ecosystem,
0 dependencies
EtwDriver/EtwDriver.sln
dotnet ecosystem,
0 dependencies
lib/krabs/krabs.sln
dotnet ecosystem,
0 dependencies
Searchable topics, generated tags, and stack labels that explain where this repository fits.
Agent instructions and tool configuration paths found in the repository tree.
Nearest indexed repositories by embedding similarity.
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
Leaking kernel addresses from ETW consumers. Requires Administrator privileges.
Enumerating and removing kernel callbacks using signed vulnerable drivers
It's pointy and it hurts!
Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods BYOVD