
KernelFlirt is a Windows kernel-level debugger with an OllyDbg/IDA Pro-style UI, built for authorized security research, reverse engineering, and malware analysis inside disposable VM labs.
| Tool | AkaTorich/KernelFlirt — Windows kernel-level debugger with UI, console REPL, and 17 plugins, MIT-licensed |
| Category | Kernel debugging / reverse engineering / dynamic malware analysis |
| Primary Use | Debugging user-mode and kernel-mode targets in an isolated VMware Windows 10 VM with testsigning enabled, using INT3, hardware DR0-DR3 breakpoints, and PDB symbols |
| Safe Use | Explicitly documented as educational and security research only, in authorized virtual machine environments with testsigning — never production systems |
| Telemetry Note | Requires a signed-off testsigning boot configuration and loads a WDM driver via KfLoader.exe; inline hooking of KdpStub and DeviceIoCtl traffic over TCP:31337 are directly observable by EDR and host-based monitoring |
KernelFlirt positions itself as a Windows kernel-level debugger wrapped in the familiar skin of classic ring-3 tools — an OllyDbg/IDA Pro-style interface that lowers the barrier for analysts who grew up on user-mode debuggers but need to walk into kernel space. The README is unusually candid about its intended deployment envelope: a host machine running the WPF UI, a Windows 10 guest with testsigning enabled, and a driver that gets loaded manually through the Service Control Manager. That three-tier split — UI, relay, driver — is the most interesting architectural decision in the whole project and reveals a deliberate safety posture: the debugger brain never runs on the machine being dissected.
The component breakdown tells the story. KernelFlirt.UI is a C#/.NET 9 WPF application running on the host. KernelFlirt.sys is a C/WDM kernel driver responsible for memory access, breakpoints, and an inline hook on KdpStub (the README also refers to it as a KdTrap inline hook). KfRelay.exe sits inside the VM and acts as a TCP proxy, translating network commands into DeviceIoCtl calls against the driver. KfLoader.exe is a small console utility that handles load, unload, and status via the SCM API. The traffic between host and guest flows over TCP:31337 on dedicated command and debug channels, which is trivially firewallable and keeps the analysis surface contained.
Two more components round out the kit. KfConsole.exe offers a WinDbg/x64dbg-style REPL front-end over the same driver and relay, for operators who prefer a terminal workflow — the README shows a sample session with connect, open, a conditional bp ntdll!NtCreateFile if rcx!=0, and a disassembly dump via u rip 5. And KernelFlirt.SDK exposes the full debugger API for plugin authors, which the project leans on heavily: all seventeen bundled plugins supposedly share this common SDK with access to memory, breakpoints, symbols, UI, events, execution control, and cross-plugin communication.
The debugging feature set reads like a checklist of everything a working analyst expects. Software breakpoints use classic INT3 patching; hardware breakpoints occupy DR0-DR3; memory breakpoints ride on PAGE_GUARD. Hardware watchpoints cover write and read/write access at 1, 2, 4, or 8 byte widths, and breakpoints can be conditional or logging. Stepping semantics follow the x64dbg convention — F7 step into, F8 step over, Ctrl+F9 step out, F4 run to cursor — and register editing extends to every GPR plus RIP, RFLAGS, and DR0-7. An inline assembler with NOP patching and patch tracking with undo rounds out the mutation tooling.
On the analysis side the tool is dense. There is a hex dump with binary pattern search supporting ?? wildcards, ASCII/Unicode string search across all loaded modules, and enumeration of modules, threads, call stacks, and SEH chains. Imports, exports, sections, and functions are all listed. Memory can be allocated, reprotected, snapshotted, and diffed — the snapshot/diff pairing in particular is a workflow feature that matters for unpacking and deobfuscation work. A RetDec-based decompiler with syntax highlighting and an IDA-style navigation bar with color-coded section maps, RIP markers, and bookmarks make long sessions navigable. PDB symbols resolve through the Microsoft Symbol Server, and RegisterFunction lets analysts persist their own function naming.
The plugin roster is where KernelFlirt shows its reverse-engineering ambitions. Graph View renders IDA-style control-flow graphs with block coloring and collapse/expand. Xrefs finds cross-references to any address. FLIRT Signatures brings function recognition by byte patterns with .pat files and a built-in MSVC CRT set — presumably the source of the project's name. Signature Detector ships 4,445 PEiD-compatible packer/compiler signatures, and PE Rebuilder does Scylla-style IAT reconstruction for dumped processes. VulnHunter scans for dangerous API usage, String Decryptor automates string recovery, and Themida Unpacker targets Themida/WinLicense protection — an aggressive inclusion that firmly anchors the tool in the malware-analysis niche.
Dynamic-analysis plugins include an API Monitor with real-time interception and parameter logging, a Network Monitor capturing send/recv/connect traffic with CSV export, and a Memory Scanner with value filtering — the classic Cheat-Engine-style scan-and-narrow loop that doubles as a solid unpacking aid. The automation tier is arguably the most modern part of the project: a Roslyn-based C# Scripting REPL with persistent state, an AI Assistant speaking to OpenAI-compatible endpoints with 65+ debugger tools exposed, and an MCP Server that lets clients like Claude Code or Cursor drive the debugger directly. An Anti-Debug Bypass plugin patches PEB, DebugPort, ThreadHideFromDebugger, and heap flags automatically — a defensive-analysis convenience that reversers will recognize as table stakes when handling protected binaries.
Session ergonomics are covered too. A Session Manager saves and restores breakpoints, comments, and function names with ASLR rebase handling, so an analysis can survive a reboot of the target VM. Bookmarks with annotations persist between sessions. Nine built-in themes — including faithful-feeling x64dbg, ollydbg, and ida-pro palettes — are switchable at runtime, with over 100 customizable color keys for operators who care about that sort of thing (and long-session analysts usually do).
Building from source requires Visual Studio 2022 with C++, WDK 10.0.26100.0 or newer, the .NET 9 SDK, and Windows 10/11 x64. A single ./build.ps1 invocation produces the full tree under bin/ — bin/Driver/, bin/Loader/, bin/Relay/, bin/UI/ with plugins and themes, and bin/Console/. Runtime is equally simple: inside the VM run KfLoader.exe load and KfRelay.exe, then on the host launch KernelFlirt.exe, connect to the VM's IP, and open a target through the File menu — the process is created suspended with an automatic entry-point breakpoint. Kernel driver debugging is reached through the Kernel Modules tab, where breakpoints can be set on any exported or symbolized function in either mode.
Documentation depth is a strong signal about project maturity. The README links an approximately 55-page SDK guide covering project setup, every API interface, threading, theming, and four complete example plugins, plus a roughly 30-page C# scripting reference with 18+ real-world recipes spanning PE analysis, IAT reconstruction, unpacker scripting, and API tracing — in both English and Russian for the SDK and scripting docs. A CLI reference for KfConsole and a changelog are also present. For a repo currently sitting at 32 stars, that documentation-to-attention ratio suggests a solo developer investing seriously in the project's long-term usability rather than chasing trends.
Operationally, the safety notes deserve emphasis. The README is explicit: VM only, testsigning enabled, not for production, because the driver modifies kernel code via the KdpStub inline hook. That hook, the unsigned driver load, and the hardcoded TCP:31337 relay port are all loud, easily-flagged artifacts — which is precisely the point. KernelFlirt is an educational and research instrument for authorized, isolated environments: analyzing malware you are permitted to analyze, auditing drivers you own, or learning Windows internals without risking a production host. Used within those boundaries, it is a remarkably complete kit; pointed at a live system, it would be both reckless and immediately visible to competent defenders.
AkaTorich/KernelFlirt.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.