360trev / PELoadFromRam
Very very useful example of loading and relocating the (Win32) DLL from memory (!) which allows many possibilities and much more flexibility to dynamically link code from many sources including realtime download from the web and also code signing!
☆21Updated 12 years ago
Alternatives and similar repositories for PELoadFromRam:
Users that are interested in PELoadFromRam are comparing it to the libraries listed below
- Ssdt Hook Detection tool☆13Updated 8 years ago
- wow64 syscall filter☆13Updated 10 years ago
- ☆25Updated 4 years ago
- TrueCrypt 7.2 — (Source Codes)☆8Updated 7 years ago
- Kernel (Ring0) - SSDT unhook driver☆14Updated 6 years ago
- An aggregate of tools used in the core of vmp_dbg plus other parsing utils to parse vmp bc.☆15Updated 8 years ago
- eyuyan image rebuild tools source code☆13Updated 8 years ago
- Lists work items being queued currently.☆13Updated 9 years ago
- does reflective dll injection☆8Updated 11 years ago
- Analysis and Modification Tool for Executables☆16Updated 5 years ago
- A library that allows hook any imported function from the IAT (works only in x64)☆11Updated 5 years ago
- Windows registry files interactive viewer☆9Updated 7 years ago
- ☆13Updated 7 years ago
- Miscellaneous IDA scripts and projects☆13Updated 3 years ago
- metasploit loader with antivirus bypass module☆17Updated 8 years ago
- ☆9Updated 8 years ago
- Windows inject☆16Updated 6 years ago
- Pafish4vs is based on [Pafish]( https://github.com/a0rtega/pafish) , just ported to the VS (VC) compiler (X64 , X86) .☆13Updated 8 years ago
- Zerokit shared code☆16Updated 5 years ago
- an efficient yet easy to use network packet builder and parser☆11Updated 7 years ago
- Tunnel IP through DNS for fun and profit (aka stealing hotel wifi)☆7Updated 6 months ago
- DNS TCP to UDP proxy☆9Updated 9 years ago
- ShellcodeOS☆10Updated 8 years ago
- HTTP/HTTPS/DNS inspector (windows driver)☆26Updated 6 years ago
- ☆7Updated 7 years ago
- Minifilter Driver☆15Updated 8 years ago
- Packer for PE and ELF, 32 and 64bits.☆22Updated 11 years ago
- Legal access: The driver and console app to demonstrate the basic memory access in kernel mode☆9Updated 7 years ago
- Final Transparent encrypted version☆14Updated 8 years ago
- User-mode process cross-checking utility intended to detect naive malware hiding itself by hooking IAT/EAT.☆19Updated 8 years ago