Fumo Loader - All in one kernel-based DLL injector
-
Updated
Jul 8, 2026 - C++
Fumo Loader - All in one kernel-based DLL injector
Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 process termination and physical memory R/W. Researching EDR-Killer patterns, PPL bypasses, and kernel-mode primitives used by MedusaLocker and other threat actors.
Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.
Vulnerable Drivers
Windows LPE exploit for CVE-2024-30804
Scans for popular vulnerable drivers that can be exploited to map unsigned driver to kernel space.
Vanguard Bypass Pro is a cutting-edge utility designed to enhance system compatibility and streamline software performance. It offers advanced environment management for a smoother and more flexible experience.
A simple writeup of an driver found in the LOLDrivers repository.
POC for vulnerable driver DrvHWX64.sys (Totally unique EDR driver exposing various functions via IOCTL)
To associate your repository with the vulnerable-driver topic, visit your repo's landing page and select "manage topics."