Skip to content

R/WPM Drvier for Windows, uses the Registry for communications.

Notifications You must be signed in to change notification settings

ALittlePatate/Revird

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Revird

Driver for x64 bit Windows, can read/write memory, get the address of a process/module in a process.

Example usage

You can find an example usage in the EdomResu folder (UserMode backwards).

int main(void) {
    QWORD proc_addr = GetProcess(L"explorer.exe");
    QWORD mod_addr = GetProcessModule(L"explorer.exe", L"kernel32.dll");
    BYTE mz = RPM<BYTE>(proc_addr);

    printf("Address of explorer.exe : 0x%p\n", (void*)proc_addr);
    printf("Address of kernel32.dll in explorer.exe : 0x%p\n", (void*)mod_addr);
    printf("Header of explorer.exe : 0x%X\n", mz);
    printf("Unloading driver...");
    DriverUnload();
    printf("ok.\n");
    return 0;
}

About

R/WPM Drvier for Windows, uses the Registry for communications.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages