ntoskrnl .data hooks for UM-KM communication
☆54May 26, 2024Updated last year
Alternatives and similar repositories for DataptrHooks
Users that are interested in DataptrHooks are comparing it to the libraries listed below
Sorting:
- Patches DSE by swapping both data ptrs located in SeValidateImageHeader && SeValidateImageData☆24Feb 9, 2024Updated 2 years ago
- a windows kernel keylogger that works☆20Feb 12, 2024Updated 2 years ago
- KDP compatible unsigned driver loader leveraging a write primitive in one of the IOCTLs of gdrv.sys☆166Jun 14, 2024Updated last year
- ☆59Feb 19, 2026Updated last month
- ☆14Aug 13, 2023Updated 2 years ago
- driver that communicates using a shared section☆93Mar 17, 2025Updated last year
- Intel 64/Windows low-level experiments☆63Aug 25, 2025Updated 6 months ago
- filter driver to hide files and directories☆25Feb 12, 2024Updated 2 years ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆17Jun 18, 2022Updated 3 years ago
- Minimalistic AMD-V/SVM hypervisor with memory introspection capabilities☆384Feb 26, 2025Updated last year
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆61Oct 19, 2024Updated last year
- PoC kernel to usermode injection☆106Feb 26, 2024Updated 2 years ago
- ☆278Sep 2, 2025Updated 6 months ago
- ☆48Jul 7, 2024Updated last year
- nmi stackwalking + module verification☆164Dec 28, 2023Updated 2 years ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆73Apr 13, 2025Updated 11 months ago
- kernel anticheat to test your driver against☆184Jun 16, 2025Updated 9 months ago
- Proof of concept on how to bypass some limitations of a manual mapped driver☆172Oct 24, 2020Updated 5 years ago
- Stealthy UM <-> KM communication system without creating any system threads, permanent hooks, driver objects, section objects or device o…☆382Mar 15, 2024Updated 2 years ago
- Modmap updated to work on Windows 11☆28Jul 30, 2021Updated 4 years ago
- load unsigned kernel-driver by patching dse in 248 lines☆146Mar 22, 2024Updated last year
- Hooking Windows' exception dispatcher to protect process's PML4☆236Jan 24, 2025Updated last year
- ☆14Dec 26, 2024Updated last year
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆159Apr 13, 2023Updated 2 years ago
- An advanced DKOM for drivers with "DRIVER_OBJECT"☆22Feb 19, 2023Updated 3 years ago
- manually map driver for a signed driver memory space☆177Mar 11, 2021Updated 5 years ago
- ☆54Mar 26, 2025Updated 11 months ago
- Anti Suspend and Detect Detaching from debuggers.☆17Apr 1, 2024Updated last year
- BOF to decrypt Signal Desktop chat logs☆70Feb 20, 2025Updated last year
- 将驱动映射到会话空间☆38Aug 27, 2022Updated 3 years ago
- 正确解析 _HEAP_VS_***符号 ,支持在最新win11 24h2 运行,替换windbg自带的!pool命令☆17Nov 30, 2024Updated last year
- A rust proof of concept to demonstrate registry overwriting via RegRestoreKey using the Offline Registry Library☆24Nov 13, 2025Updated 4 months ago
- A lexer and parser for Sleep☆20Feb 20, 2026Updated last month
- kernel mode anti cheat☆646Aug 4, 2024Updated last year
- A mapper that maps shellcode into loaded large page drivers☆329Apr 26, 2022Updated 3 years ago
- usermode driver mapper that forcefully loads any signed kernel driver (legit cert) with a big enough section (example: .data, .rdata) to …☆475Jan 3, 2022Updated 4 years ago
- Windows driver mapper via the UEFI☆58Jul 13, 2025Updated 8 months ago
- devirtualizer for memevm☆17May 26, 2020Updated 5 years ago
- This is my EAC Bypass (Setup) Driver that offers an undetected communication and callback handler/hooking system through IOCTL.☆173Sep 27, 2025Updated 5 months ago