0xjbb/EyYoEtwWhereYouAt
Correlating kernel notifications with the lack of ETW events to detect ETW Patching
Leaking kernel addresses from ETW consumers. Requires Administrator privileges.
Appears on
Quick read
Latest capture 2026-07-30 03:05
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
3 observed captures since 2026-06-24. Charts use measured snapshots only.
Stars from first capture 0
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Correlating kernel notifications with the lack of ETW events to detect ETW Patching
Poc exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
It's pointy and it hurts!
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques