0xjbb/EyYoEtwWhereYouAt
Correlating kernel notifications with the lack of ETW events to detect ETW Patching
Leaking kernel addresses from ETW consumers. Requires Administrator privileges.
Appears on
Quick read
Latest capture 2026-09-02 03:07
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
4 observed captures since 2026-06-24. Observed captures are shown by default.
Stars from first capture 0
Observed captures only
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Correlating kernel notifications with the lack of ETW events to detect ETW Patching
Poc exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
It's pointy and it hurts!
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques