A-Normal-User / NtSocket_NtClient_NtServerLinks
Using NtCreateFile and NtDeviceIoControlFile to realize the function of winsock(利用NtCreateFile和NtDeviceIoControlFile 实现winsock的功能)
☆111Updated 2 years ago
Alternatives and similar repositories for NtSocket_NtClient_NtServer
Users that are interested in NtSocket_NtClient_NtServer are comparing it to the libraries listed below
Sorting:
- 利用物理内存映射,实现虚拟内存的伪隐藏☆83Updated 2 years ago
- sc4cpp is a shellcode framework based on C++☆90Updated 3 years ago
- Another wow64ext to try to be compatible with WOW64 for all architectures.☆95Updated this week
- Hook NtDeviceIoControlFile with PatchGuard☆109Updated 3 years ago
- Quick check of NT kernel exported&unexported functions/global variable offset NT内核导出以及未导出函数+全局变量偏移速查☆95Updated 2 years ago
- Based on minhook☆31Updated last year
- Call NtCreateUserProcess directly as normal.☆72Updated 3 years ago
- ☆53Updated 2 years ago
- c++ implementation of windows heavens gate☆72Updated 4 years ago
- CVE-2022-3699 with arbitrary kernel code execution capability☆71Updated 2 years ago
- ☆27Updated last year
- It's a kernel-based keylogger for Windows x86/x64.☆141Updated 2 years ago
- Enum and Remove Hook in Windows☆38Updated 2 weeks ago
- a monitoring windows driver calls kernel api tools☆110Updated last year
- Windows kernel drivers simple HTTP library for modern C++☆42Updated 7 years ago
- A x64 PE Packer/Protector Developed in C++ and VisualStudio☆52Updated last year
- ☆65Updated 6 years ago
- Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.☆88Updated 2 months ago
- an encryption library designed for Windows kernel and driver programming☆117Updated last year
- a ntdll.h head file which download from network, and fix all found problems by me.☆32Updated 7 months ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆64Updated 11 months ago
- ☆80Updated 3 years ago
- SymbolTypeViewer_汉化☆17Updated 4 years ago
- 不使用3环挂钩进行DWM桌面绘制☆82Updated 3 years ago
- 收集常用windows版本内核文件☆34Updated last year
- ☆18Updated 9 months ago
- 可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。☆111Updated 2 years ago
- Compile-Time Calls Obfuscator for C++14+☆48Updated last year
- bootkit驱动映射,三环进程注入加载指定模块☆14Updated 9 months ago
- ☆70Updated 3 years ago