ntoskrnl .data hooks for UM-KM communication
☆52May 26, 2024Updated 2 years ago
Alternatives and similar repositories for DataptrHooks
Users that are interested in DataptrHooks are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Patches DSE by swapping both data ptrs located in SeValidateImageHeader && SeValidateImageData☆25Feb 9, 2024Updated 2 years ago
- a windows kernel keylogger that works☆20Feb 12, 2024Updated 2 years ago
- KDP compatible unsigned driver loader leveraging a write primitive in one of the IOCTLs of gdrv.sys☆171Jun 14, 2024Updated 2 years ago
- ☆59Jun 10, 2026Updated 2 weeks ago
- ☆15Aug 13, 2023Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Windows kernel driver demonstrating kernel-to-usermode communication via shared memory sections☆109Apr 24, 2026Updated 2 months ago
- filter driver to hide files and directories☆28Feb 12, 2024Updated 2 years ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆16Jun 18, 2022Updated 4 years ago
- Minimalistic AMD-V/SVM hypervisor with memory introspection capabilities☆417Feb 26, 2025Updated last year
- Intel 64/Windows low-level experiments☆105Jun 7, 2026Updated 3 weeks ago
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆64Oct 19, 2024Updated last year
- Windows kernel anti-cheat for driver integrity testing and security research☆190Jun 16, 2025Updated last year
- PoC kernel to usermode injection☆125Feb 26, 2024Updated 2 years ago
- ☆48Jul 7, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- nmi stackwalking + module verification☆171Dec 28, 2023Updated 2 years ago
- ☆292Sep 2, 2025Updated 9 months ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆81Apr 13, 2025Updated last year
- Proof of concept on how to bypass some limitations of a manual mapped driver☆169Oct 24, 2020Updated 5 years ago
- Stealthy UM <-> KM communication system without creating any system threads, permanent hooks, driver objects, section objects or device o…☆388Apr 30, 2026Updated 2 months ago
- Modmap updated to work on Windows 11☆28Jul 30, 2021Updated 4 years ago
- load unsigned kernel-driver by patching dse in 248 lines☆149Mar 22, 2024Updated 2 years ago
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆159Mar 16, 2026Updated 3 months ago
- ☆14Dec 26, 2024Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Hooking Windows' exception dispatcher to protect process's PML4☆257Jan 24, 2025Updated last year
- An advanced DKOM for drivers with "DRIVER_OBJECT"☆23Feb 19, 2023Updated 3 years ago
- manually map driver for a signed driver memory space☆181Mar 11, 2021Updated 5 years ago
- kernel mode anti cheat☆668Aug 4, 2024Updated last year
- ☆56Mar 26, 2025Updated last year
- Anti Suspend and Detect Detaching from debuggers.☆17Apr 1, 2024Updated 2 years ago
- 将驱动映射到会话空间☆39Aug 27, 2022Updated 3 years ago
- BOF to decrypt Signal Desktop chat logs☆70Feb 20, 2025Updated last year
- 正确解析 _HEAP_VS_***符号 ,支持在最新win11 24h2 运行,替换windbg自带的!pool命令☆17Nov 30, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A rust proof of concept to demonstrate registry overwriting via RegRestoreKey using the Offline Registry Library☆24Nov 13, 2025Updated 7 months ago
- A lexer and parser for Sleep☆20Feb 20, 2026Updated 4 months ago
- Windows driver mapper via the UEFI☆66Jul 13, 2025Updated 11 months ago
- usermode driver mapper that forcefully loads any signed kernel driver (legit cert) with a big enough section (example: .data, .rdata) to …☆499Jan 3, 2022Updated 4 years ago
- devirtualizer for memevm☆18May 26, 2020Updated 6 years ago
- A mapper that maps shellcode into loaded large page drivers☆365Apr 26, 2022Updated 4 years ago
- This is my EAC Bypass (Setup) Driver that offers an undetected communication and callback handler/hooking system through IOCTL.☆197Apr 23, 2026Updated 2 months ago