github Actively maintained

hugsy/CFB

CFB is a ProcMon-style tool designed to assist capturing IRPs sent to Windows drivers.

1 awesome list

Quick read

Stars
337
Forks
68
Open issues
2
Commits
483

Activity and growth

Latest capture 2026-09-02 03:07

Stars · last 7 days
No history
Commits · last 7 days
No history
Stars since tracking
+2
Stored snapshots
4

Classification

Metadata

Language
C++
Default branch
main
Created
2018-07-31
First commit
2018-07-29
Last pushed
2024-03-26
GitHub updated
2026-08-28
Last synced
2026-09-02 03:07
Stack scanned
2026-09-02 03:07
Archived
No

AI development signals

0 paths

Agent instructions and tool configuration found in this repository.

No config files detected.

Growth history

Tracked growth

4 observed captures since 2026-06-24. Observed captures are shown by default.

Stars from first capture +2

Chart data

Observed captures only

Time horizon

All tracked data

Custom date range

Stars history

Observed snapshots

Commits history

Observed snapshots

Similar repositories

Nearest indexed repositories by embedding similarity.

0xDbgMan/DrvEye

Static analysis & exploitation-triage toolkit for Windows kernel drivers. Discover IOCTLs, Symbolic Links, and check cert , and Downlaods BYOVD

199 stars
Python 1 awesome list

br-sn/CheekyBlinder

Enumerating and removing kernel callbacks using signed vulnerable drivers

592 stars
C++ 1 awesome list

simsong/tcpflow

TCP/IP packet demultiplexer. Download from:

1,774 stars
C++ 1 awesome list

0vercl0k/wtf

wtf is a distributed, code-coverage guided, customizable, cross-platform snapshot-based fuzzer designed for attacking user and / or kernel-mode targets running on Microsoft Windows and Linux user-mode (experimental!).

1,798 stars
C++ 1 awesome list