Profile
- Location
- Warszawa
- City
- Warszawa
- Public repositories
- 23
GitHub
Snapshot:
KVC enables unsigned driver loading via DSE bypass (g_CiOptions patch, skci.dll hijack, SeCiCallbacks redirection) and PP/PPL manipulation for LSASS memory dumping on modern Windows with HVCI/VBS.
Windows 11 kernel research framework demonstrating DSE bypass on Windows 11 25H2 through boot-time execution. Loads unsigned drivers by surgically patching SeCiCallbacks via native subsystem. Includes anti-loop protection and dual-path architecture. Windows 11 25H2 driver signature enforcement bypass
Advanced native-mode utility for bypassing DSE and HVCI. Implements smart SeCiCallbacks patching and independent management of Memory Integrity settings. Operating as a subsystem:native app, it ensures early-phase control and environment preparation for security research and driver development.
Advanced AV/EDR Killer: Specialized Antivirus & Windows Defender killer for security professionals. Utilizes kernel-level IOCTLs for process termination and IFEO registry techniques to prevent service recovery. Offers deterministic x64 builds, SCM-based restoration, and a modern Win32 UI. Built for researching process protection and EDR bypasses