gmh5225/BYOVD
Some POCs for my BYOVD research and find some vulnerable drivers
Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when attackers disable standard process notify callbacks.
Appears on
Quick read
Latest capture 2026-07-29 03:08
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
3 observed captures since 2026-06-24. Charts use measured snapshots only.
Stars from first capture -1
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Some POCs for my BYOVD research and find some vulnerable drivers
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
Kernel Driver Utility
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
It's pointy and it hurts!
Poc exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY