2 repositories on SrcLog
PoCs and tools for investigation of Windows process execution techniques
Kernel mode WinDbg extension and PoCs for token privilege investigation.