Cr4sh/KernelForge
A library to develop kernel level Windows payloads for post HVCI era
Repository profile
The Definitive Guide To Process Cloning on Windows
Repository updates
Get generated huntandhackett/process-cloning development summaries by email, or follow the weekly and monthly RSS feeds.
Sign in to subscribe by email. RSS feeds are public.
Sign in to subscribeTracked growth, recent movement, and commit velocity from stored repository snapshots.
Latest capture 2026-06-24 13:55
1 capture since 2026-06-24
Stars from baseline 0
All tracked data
Frameworks, package managers, ecosystems, and dependency manifests found during catalog scans.
Scanned 2026-06-24 13:55
1.NtCreateUserProcess/NtCreateUserProcess.sln
dotnet ecosystem,
0 dependencies
2.RtlCloneUserProcess/RtlCloneUserProcess.sln
dotnet ecosystem,
0 dependencies
3.CloneAndMinidump/CloneAndMinidump.sln
dotnet ecosystem,
0 dependencies
4.InspectClonedMemory/InspectClonedMemory.sln
dotnet ecosystem,
0 dependencies
5.Library/Example.sln
dotnet ecosystem,
0 dependencies
Searchable topics, generated tags, and stack labels that explain where this repository fits.
Agent instructions and tool configuration paths found in the repository tree.
Nearest indexed repositories by embedding similarity.
A library to develop kernel level Windows payloads for post HVCI era
Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999
Hypervisor based anti anti debug plugin for x64dbg
🪛 Rust powered precision file tools for AI agents thats minimize context use: patch-based edits, kernel-enforced path confinement. Dramatically fewer tokens than naive read/write. MCP Server or embeddable, bring your own MCP (Rust, Python, Nodejs). Come with Skills.md (npx skills add ckanthony/Chisel)
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
This program is designed to demonstrate various process injection techniques