Satoshi Tanda (@tandasat)

Top repositories

1

HyperPlatform

Intel VT-x based hypervisor aiming to provide a thin VM-exit filtering platform on Windows.
C++
1,438
star
2

DdiMon

Monitoring and controlling kernel API calls with stealth hook using EPT
C++
1,086
star
3

Hypervisor-101-in-Rust

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application for high-performance fuzzing on Intel/AMD processors.
Rust
935
star
4

MiniVisorPkg

The research UEFI hypervisor that supports booting an operating system.
C
478
star
5

SimpleSvmHook

SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.
C++
313
star
6

PgResarch

PatchGuard Research
C++
282
star
7

SimpleSvm

A minimalistic educational hypervisor for Windows on AMD processors.
C++
262
star
8

ExploitCapcom

This is a standalone exploit for a vulnerable feature in Capcom.sys
C++
258
star
9

MemoryMon

Detecting execution of kernel memory where is not backed by any image file
C++
239
star
10

DotNetHooking

Sample use cases of the .NET native code hooking technique
C#
202
star
11

scripts_for_RE

Python scripts for reverse engineering.
Python
173
star
12

GuardMon

Hypervisor based tool for monitoring system register accesses.
C++
141
star
13

UefiVarMonitor

The runtime DXE driver monitoring access to the UEFI variables by hooking the runtime service table.
C
132
star
14

SmmExploit

The report and the exploit of CVE-2021-26943, the kernel-to-SMM local privilege escalation vulnerability in ASUS UX360CA BIOS version 303.
122
star
15

EopMon

Elevation of privilege detector based on HyperPlatform
C++
119
star
16

Sushi

a Japanese food keeps you sane
C++
115
star
17

findpg

Windbg extension to find PatchGuard pages
C++
113
star
18

UEFI-BIOS-Security

Security Camp 2021 & GCC 2022
107
star
19

hvext

The Windbg extension that implements commands helpful to study Hyper-V on Intel processors.
JavaScript
105
star
20

WinIoCtlDecoder

IDA Plugin which decodes Windows Device I/O control code into DeviceType, FunctionCode, AccessType and MethodType.
Python
102
star
21

HelloSmm

This is an instruction to run your own SMM code.
C
95
star
22

DebugLogger

A software driver that lets you log kernel-mode debug output into a file on Windows.
C++
95
star
23

WPBT-Builder

The simple UEFI application to create a Windows Platform Binary Table (WPBT) from the UEFI shell.
C
91
star
24

FU_Hypervisor

A hypervisor hiding user-mode memory using EPT
C
90
star
25

CVE-2023-36427

Report and exploit of CVE-2023-36427
C++
89
star
26

kraft_dinner

Tool to dump UEFI runtime drivers implementing runtime services for Windows
C
85
star
27

HelloAmdHvPkg

HelloAmdHvPkg is a type-1 research hypervisor for AMD processors.
C
83
star
28

Hello-VT-rp

A simple hypervisor demonstrating the use of the Intel VT-rp (redirect protection) technology.
Rust
80
star
29

RemoteWriteMonitor

A tool to help malware analysts tell that the sample is injecting code into other process.
C++
73
star
30

Scavenger

A minifilter driver preserves all modified and deleted files.
C
71
star
31

meow

nyā
C++
70
star
32

HelloIommuPkg

The sample DXE runtime driver demonstrating how to program DMA remapping.
C
57
star
33

DumpVTable

Generates a Python script to give public interface names in an ActiveX file to an IDB file.
C++
45
star
34

DrvLoader

A command line tool to load and unload a device driver.
C++
42
star
35

CVE-2022-25949

A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.
C++
35
star
36

cs_driver

A sample project for using Capstone from a driver in Visual Studio 2015
C
34
star
37

CVE-2014-0816

CVE-2014-0816
C++
24
star
38

CVE-2024-21305

Report and exploit of CVE-2024-21305.
C++
24
star
39

hyperplatform_log_parser

User-mode program parsing logs created by HyperPlatform
C++
18
star
40

tandasat.github.io

HTML
17
star
41

ProjectLoadTimeMonitor

The Visual Studio extension that measures load time of each project when a solution file is opened.
C#
16
star
42

CheckSDL

A tool evaluates security configurations of a given PE based on SDL without source code
C++
12
star
43

ListWorkItems

Lists work items being queued currently.
C++
12
star
44

DeviceOpener

A command line tool to check if a specified device is accessible.
C++
10
star
45

windbg_init

Windbg Init Script
9
star
46

win32_debugout

Shows debug strings on DebubView from an attached process by win32_remote.exe.
C++
8
star
47

ping_vmm

A user-mode program knocking at HyperPlatform's "backdoor"
C++
7
star
48

List-UEFI-Configuration-Tables

List UEFI Configuration Tables
Rust
7
star
49

ScopedResource

Scoped Resource - Generic RAII Wrapper for the Standard Library by Peter Sommerlad and Andrew L. Sandoval
C++
6
star
50

SecRuntimeSample

A sample usege of SecRuntime.dll on Windows Phone
C++
4
star
51

blog

Ruby
4
star
52

CopyFiles

Copy files onto the IsolatedStorage so that you can download them using IsoStoreSpy.
C#
3
star
53

mylight

Using LED of Samsung Galaxy Ace S5830
Java
2
star
54

tandasat

2
star
55

shared

Manages files that are shared with multiple boxes.
Vim Script
1
star