.NET library for hooking and dumping Clr
☆44Jun 11, 2024Updated last year
Alternatives and similar repositories for ClrAnalyzer
Users that are interested in ClrAnalyzer are comparing it to the libraries listed below
Sorting:
- POC about how to prevent windbg break☆15Oct 3, 2022Updated 3 years ago
- Simple JIT compiler hook in C#☆91May 13, 2014Updated 11 years ago
- Easily hook WIN32 x64 functions☆18Feb 19, 2025Updated last year
- Dump PDB Symbols including support for Bochs Debugging Format (with wine support)☆14Aug 11, 2023Updated 2 years ago
- A managed .NET Jit hooking library.☆15Dec 3, 2019Updated 6 years ago
- JITM is an automated tool to bypass the JIT Hooking protection on a .NET sample.☆56Dec 11, 2020Updated 5 years ago
- Example JIT Hook for .NET FW/Core.☆54Feb 21, 2020Updated 6 years ago
- 参考taviso的代码逆向一下mpengine.dll☆20Jun 30, 2022Updated 3 years ago
- ☆33Jul 6, 2020Updated 5 years ago
- Open-source EDR kernel-component for system monitoring and DLL injection☆33Nov 14, 2020Updated 5 years ago
- Undocumented NsiAllocateAndGetTable usage in GetTcpTableInternal reverse engineered on Win7 X64☆20Apr 7, 2018Updated 7 years ago
- Demo to show how write ALPC Client & Server using native Ntdll.dll syscalls.☆21Jan 25, 2022Updated 4 years ago
- Sample use cases of the .NET native code hooking technique☆218Feb 9, 2018Updated 8 years ago
- A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.☆41Dec 31, 2020Updated 5 years ago
- Lightweight and flexible .NET packer☆21Apr 25, 2018Updated 7 years ago
- Nasha is a Virtual Machine for .NET files and its runtime was made in C++/CLI☆80Aug 28, 2021Updated 4 years ago
- Inject a .NET assembly into a native process using the CLR Hosting API☆21Apr 28, 2018Updated 7 years ago
- Simple Demo of using Windows Hypervisor Platform☆29Jul 14, 2025Updated 7 months ago
- x64 Kernel Hooks Detection☆24Jan 1, 2017Updated 9 years ago
- ☆81Feb 12, 2022Updated 4 years ago
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆23Nov 22, 2021Updated 4 years ago
- Pure Go bindings for Zydis.☆13Jul 14, 2024Updated last year
- Modded version of KoiVM☆12Aug 17, 2019Updated 6 years ago
- A simple open source c++ kernel injector i made for project nova.☆14Dec 24, 2023Updated 2 years ago
- ☆15Mar 28, 2015Updated 10 years ago
- Windows CIFS/SMB packet generation and SMB networking library☆12Aug 25, 2020Updated 5 years ago
- A simple process query/manipulation tool using driver hooked system call. (2019)☆12Aug 30, 2021Updated 4 years ago
- A dnlib port of ILProtectorUnpacker. Contains slight modifications and improvements.☆11Dec 27, 2020Updated 5 years ago
- A dnSpy extension to hot-reload themes☆12Dec 27, 2020Updated 5 years ago
- ☆26Dec 29, 2021Updated 4 years ago
- x64 Windows implementation of virtual-address to physical-address translation☆48Jun 3, 2021Updated 4 years ago
- map driver to memory☆26Aug 26, 2018Updated 7 years ago
- Yet another CawkVM unpacker...☆80Feb 24, 2023Updated 3 years ago
- R3劫持所有异常☆15Jan 4, 2021Updated 5 years ago
- ☆10Nov 11, 2020Updated 5 years ago
- A collection of cpuid instruction implementations for anti-vm purposes.☆10Oct 5, 2023Updated 2 years ago
- Writing Your Own Ticket to the Cloud Like APT: A Deep-dive to AD FS Attacks, Detections, and Mitigations☆12Dec 9, 2022Updated 3 years ago
- Windows system spy for Mouse, Keyboard and Gamepad(Joystick).☆15Jul 6, 2022Updated 3 years ago
- TrinitySeal patcher.☆10Nov 26, 2019Updated 6 years ago