0xDbgMan/DrvEye
Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods BYOVD
CFB is a ProcMon-style tool designed to assist capturing IRPs sent to Windows drivers.
Appears on
Quick read
Latest capture 2026-09-02 03:07
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
4 observed captures since 2026-06-24. Observed captures are shown by default.
Stars from first capture +2
Observed captures only
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods BYOVD
It's pointy and it hurts!
Enumerating and removing kernel callbacks using signed vulnerable drivers
TCP/IP packet demultiplexer. Download from:
Debugger Anti-Detection Benchmark
wtf is a distributed, code-coverage guided, customizable, cross-platform snapshot-based fuzzer designed for attacking user and / or kernel-mode targets running on Microsoft Windows and Linux user-mode (experimental!).