0mWindyBug / DataptrHooks
ntoskrnl .data hooks for UM-KM communication
☆34Updated 5 months ago
Related projects ⓘ
Alternatives and complementary repositories for DataptrHooks
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆30Updated 7 months ago
- PoC kernel to usermode injection☆59Updated 8 months ago
- Kernel Level NMI Callback Blocker☆32Updated 2 months ago
- A method to Disable DSE using .data ptr hooks☆26Updated 9 months ago
- POC Hook of nt!HvcallCodeVa☆50Updated last year
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆23Updated last month
- PAGE_GUARD based hooking library☆40Updated 2 years ago
- This is an EfiGuard BootLoader that can boot EfiGuard from Usermode with no USB or Setup as a Single Executable with automatic File Dumpi…☆30Updated 2 months ago
- Compileable POC of namazso's x64 return address spoofer.☆47Updated 4 years ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆46Updated last year
- DSE & PG bypass via BYOVD attack☆37Updated 7 months ago
- ☆24Updated last month
- Experiment with PAGE_GUARD protection to hide memory from other processes☆39Updated 4 months ago
- Patches DSE by swapping both data ptrs located in SeValidateImageHeader && SeValidateImageData☆19Updated 9 months ago
- A simple kernel driver for R/W Using kSockets with some bypass implementation overall I wouldn't say its "ud"☆44Updated 2 months ago
- Injecting dll to protected games using ioclt and code cave communications, works on eac, be protected games but made for fn☆53Updated 7 months ago
- A Kernel Driver that can be used for a cheat or malware base to circumvent common cache & structure table checks. PsLoadedModuleList howe…☆74Updated 2 months ago
- Windows PDB parser for kernel-mode environment.☆90Updated last year
- A library to assist with memory & code protection.☆53Updated 8 months ago
- hidden_syscall - syscaller without using syscall instruction in code☆58Updated last year
- My EAC & BE Rady CR3 Reading & Writing source that I use for my KM Drivers.☆44Updated 2 months ago
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆41Updated last year
- ☆50Updated 11 months ago
- partially disable patchguard up to win11 21H2☆16Updated 5 months ago
- Windows driver mapper via the UEFI☆38Updated last week
- ☆37Updated 4 months ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆40Updated last year