A forum for reverse engineering, OS internals and malware analysis 

Forum for discussion about kernel-mode development.
Forum Statistics Last post
[Kernel] Memory dumper / Forensics tools
by iSecure  - Wed May 02, 2012 11:04 am
10 Replies 
 14749 Views
 by p4r4n0id
 Sun Mar 31, 2013 1:21 pm
Implementing Branch Trace in UserMode
by zico_guru  - Mon Mar 18, 2013 8:06 am
8 Replies 
 8382 Views
 by _Lynn
 Tue Mar 26, 2013 2:22 pm
Easy synchronous usermode call?
by takep  - Fri Mar 15, 2013 10:09 am
3 Replies 
 4572 Views
 by takep
 Thu Mar 21, 2013 1:34 pm
7 Replies 
 7639 Views
 by myid
 Thu Feb 14, 2013 3:43 pm
14 Replies 
 19438 Views
 by EP_X0FF
 Wed Feb 13, 2013 12:49 pm
How to verify digital signature on driver?
by myid  - Sat Jan 26, 2013 4:47 pm
1 Replies 
 3244 Views
 by rinn
 Sun Jan 27, 2013 11:58 am
2 Replies 
 3912 Views
 by takep
 Mon Jan 07, 2013 8:17 pm
How to get GDT information on X64?
by myid  - Sat Dec 29, 2012 1:33 pm
3 Replies 
 4256 Views
 by feryno
 Mon Dec 31, 2012 10:10 am
How to get unloaded kernel module list?
by myid  - Fri Dec 14, 2012 9:31 pm
4 Replies 
 4901 Views
 by myid
 Fri Dec 21, 2012 11:30 am
Process Exceptions in x64
by p4r4n0id  - Wed Dec 12, 2012 1:50 pm
4 Replies 
 4709 Views
 by feryno
 Fri Dec 14, 2012 10:29 am
1 Replies 
 7520 Views
 by EP_X0FF
 Mon Dec 10, 2012 3:35 am
Self protection without hooks
by Tigzy  - Thu Nov 29, 2012 7:52 pm
13 Replies 
 12289 Views
 by EP_X0FF
 Sun Dec 02, 2012 1:58 pm
Kernel inline hooking
by p4r4n0id  - Thu Nov 29, 2012 9:11 pm
5 Replies 
 5496 Views
 by EP_X0FF
 Sat Dec 01, 2012 4:12 am
Getting the PEB address through EPROCESS
by Stylo  - Mon Nov 26, 2012 5:50 pm
15 Replies 
 14737 Views
 by Stylo
 Tue Nov 27, 2012 9:11 pm
minifilter load
by Tigzy  - Fri Nov 16, 2012 2:45 pm
4 Replies 
 4593 Views
 by Tigzy
 Fri Nov 16, 2012 3:29 pm
Reading buffer from a device
by Stylo  - Mon Nov 12, 2012 8:04 am
2 Replies 
 3388 Views
 by Stylo
 Thu Nov 15, 2012 7:26 pm
Write bus driver for Win7 and register an ISR
by Vmrun  - Thu Sep 06, 2012 7:16 am
1 Replies 
 2951 Views
 by m5home
 Mon Nov 05, 2012 8:08 am
GUI or console?
by George118  - Thu Oct 25, 2012 4:32 pm
9 Replies 
 9411 Views
 by EP_X0FF
 Sun Oct 28, 2012 12:37 pm
CmRegisterCallbackEx Questions.
by __fastcall  - Sun Oct 21, 2012 7:51 pm
11 Replies 
 10966 Views
 by xdeadcode
 Wed Oct 24, 2012 6:43 pm
modify EPROCESS token Object
by R00tKit  - Wed Oct 24, 2012 6:11 am
1 Replies 
 2806 Views
 by R00tKit
 Wed Oct 24, 2012 1:00 pm
Registry Editing as a driver
by Pwnilicious  - Sun Oct 14, 2012 2:21 pm
1 Replies 
 3090 Views
 by cjbi
 Sun Oct 14, 2012 3:19 pm
2 Replies 
 3602 Views
 by Vrtule
 Sat Sep 29, 2012 4:05 pm
Page Directory/Table
by _MAX_  - Sat Sep 22, 2012 11:54 pm
3 Replies 
 3832 Views
 by R00tKit
 Sun Sep 23, 2012 11:32 am
19 Replies 
 13089 Views
 by p30arena
 Sun Sep 16, 2012 2:27 pm
Enumerating Active FileSystem Devices
by p30arena  - Thu Sep 06, 2012 7:37 pm
8 Replies 
 7081 Views
 by p30arena
 Fri Sep 07, 2012 9:29 am
  • 1
  • 7
  • 8
  • 9
  • 10
  • 11
  • 14