Wezo
GitHub
30 repos
905 followers
Explained projects
Ophion: The Hypervisor That Lies to the Clock
How a stealth Type-2 hypervisor uses micro-architectural time compensation and private memory boundaries to subsume Windows and evade modern anti-cheats.
7 min read ยท Apr 3, 2026
Yet to be explained
ZeroHVCI
Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers.
C
293 stars
Explain
GoodmansKernel
Run unsigned kernel payloads in a signed kernel driver via wasm3. No JIT/W^x (HVCI/etc., compliant)
C
151 stars
Explain
BusterCall
"Bypassing" HVCI via donor PFN swaps to modify read-only code pages. Call chained kernel functions (kCET and SLAT support), and more.
C
141 stars
Explain
NTMemory
Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.
C++
93 stars
Explain
AsusDrv
Abusing AsusBiosIoDrv64.sys to gain kernel and process physical/virtual memory access.
C++
30 stars
Explain
x670e-tomahawk-anticheat-update
Reverse of MSI's MAG X670E TOMAHAWK WIFI bios v1KB (2026-03-20) which claims "Implemented the anti-cheat mechanism" in the release notes.
18 stars
Explain
hv
C
11 stars
Explain
miVault
simple program for xorcrypting and storing files into media files like audios, images and videos while maintaining integrity.
C++
10 stars
Explain
xSIMD
Cross-platform SIMD assembler that emits unified vector instructions to native x86, ARM, and RISC-V machine code.
C
8 stars
Explain
gexec
Register-machine bytecode interpreter for Windows kernel drivers.
C++
6 stars
Explain
zer0condition.github.io
HTML
0 stars
Explain