Igor Korkin

Igor Korkin

@IgorKorkin

◾Cyber Security researcher & expert. ◾OSes, hypervisors, malware, and protection technologies, including their limitations. ◾Speaker, author & developer.

128
Followers
103
Following
107
Public Repos
0
Private Repos

Language Breakdown

Lines of code distribution across 17 owned repositories

20.8M Total LOC
C++
12,453,506 lines
59.7%
N/A
C
4,762,796 lines
22.8%
N/A
Smalltalk
1,078,148 lines
5.2%
N/A
Java
789,006 lines
3.8%
N/A
Python
618,200 lines
3.0%
N/A
Other
1,142,148 lines
5.5%
N/A
T

T-Shaped Developer

T-shaped

Deep in C++ with broad versatility

C++
C
Smalltalk
Java
Python

Collaboration Network

Global Impact visualization

LIVE
Igor Korkin
0 active collaborators

Repos

110

PRs

0

Growth

+18%

Top Collaborators

No collaborator data yet.

Coding Streak

Contribution activity over the past year

2 days
214
Contributions
89
Commits
7
Pull Requests
Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun
Mo
We
Fr
Based on GitHub activity
Less
More

Top Repositories

MemoryRanger

MemoryRanger protects kernel data and code by running drivers and hosting data in isolated kernel enclaves using VT-x and EPT features. MemoryRanger has been presented at the BlackHat, HITB, CDFSL.

244 68
C++
HypervisorsDetection

This is the first software system, which can detect a stealthy hypervisor and calculate several nested ones even under countermeasures.

91 26
C++
AllMemPro

AllMemPro

46 11
C++
MemAttacker

This project demonstares an illegal read- and write- access to the kernel-mode data for both allocated by 3rd party drivers and EPROCESS structures

13 7
C++
AllMemProTestBed

Legal access: The driver and console app to demonstrate the basic memory access in kernel mode

9 3
C++
PPL

The demo of RtlTestProtectedAccess() and RtlProtectedAccess involved in creation Protected Process.

8 0
C++
MemAllocator

This project demonstrates allocation and legal access to the allocated data in the kernel mode.

6 4
C++
AllMemProTestBedPatcher

Illegal access: the driver and console app to demo unauthorized read- and write- access to the kernel-mode memory

5 4
C++
research

The section includes all the information about my research result: papers, slides, speeches, etc.

4 2
HTML
testbed

This project demonstrates the privilege escalation for a user-mode process - cmd.exe using stack overflow in the kernel mode driver. The user-mode component 'testbed_console.exe' sends CTL_CODE with a payload to the vulnerable driver 'testbed_driver.sys', which call RtlCopyMemory without any checks. 'testbed_console.exe' includes 'testbed_driver.sys' has a resource.

4 4
C++

Open Source Impact

Contributions to external projects

8 merged PRs
Contributed to 1 repositories