利用物理内存映射,实现虚拟内存的伪隐藏
☆86Sep 15, 2022Updated 3 years ago
Alternatives and similar repositories for Pretend_HideVirtualMemory
Users that are interested in Pretend_HideVirtualMemory are comparing it to the libraries listed below
Sorting:
- Using NtCreateFile and NtDeviceIoControlFile to realize the function of winsock(利用NtCreateFile和NtDeviceIoControlFile 实现winsock的功能)☆128Sep 9, 2022Updated 3 years ago
- 不使用3环挂钩进行DWM桌面绘制☆82Dec 9, 2021Updated 4 years ago
- Windows X64 mode use seh in manual mapped dll or manual mapped sys☆80Oct 10, 2022Updated 3 years ago
- Kernel dwm render☆168Oct 10, 2023Updated 2 years ago
- ☆56Nov 21, 2022Updated 3 years ago
- 研究和移除各种内核回调,在anti anti cheat的路上越走越远☆183Aug 26, 2022Updated 3 years ago
- first commit☆64Oct 29, 2020Updated 5 years ago
- A kernel mode Windows rootkit in development.☆49Dec 31, 2021Updated 4 years ago
- 从MmPfnData中枚举进程和页目录基址☆205Aug 18, 2023Updated 2 years ago
- 将shellcode注入dwm.exe以进行屏幕截取☆356Mar 22, 2022Updated 3 years ago
- The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).☆284Jan 27, 2025Updated last year
- an encryption library designed for Windows kernel and driver programming☆123Aug 4, 2023Updated 2 years ago
- ☆174Mar 9, 2022Updated 3 years ago
- Using C++ STL on Windows kernle development☆91Feb 21, 2019Updated 7 years ago
- 简单安排一下 autochk.sys 这个rootkit☆73Mar 7, 2023Updated 2 years ago
- ☆144Dec 10, 2022Updated 3 years ago
- (shard of furikuri project) assambler for code obfuscation☆19Oct 29, 2019Updated 6 years ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆145Sep 3, 2023Updated 2 years ago
- Lightweight Intel VT-x Hypervisor.☆661Dec 17, 2024Updated last year
- Another wow64ext to try to be compatible with WOW64 for all architectures.☆98Jan 1, 2026Updated last month
- 内核级别隐藏指定窗口☆320Feb 9, 2022Updated 4 years ago
- ☆193May 1, 2023Updated 2 years ago
- All Nt Syscall and W32k Syscall in one asm, include, and call it!☆58Nov 4, 2021Updated 4 years ago
- https://key08.com/index.php/2021/10/19/1375.html☆71May 11, 2022Updated 3 years ago
- sc4cpp is a shellcode framework based on C++☆95Aug 29, 2021Updated 4 years ago
- query-pdb is a server-side software for parsing PDB files. The software provides PDB online parsing service.☆168Oct 27, 2025Updated 4 months ago
- Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode☆163Jul 31, 2022Updated 3 years ago
- a monitoring windows driver calls kernel api tools☆126Jul 5, 2024Updated last year
- a frame of amd-v svm nest☆53Apr 7, 2020Updated 5 years ago
- ☆47Feb 3, 2025Updated last year
- anti cheat drv open source☆19Apr 18, 2024Updated last year
- Load Dll into Kernel space☆40Aug 23, 2022Updated 3 years ago
- ShotHv☆154Mar 8, 2022Updated 3 years ago
- Win7内核私有符号结构转储☆70Sep 3, 2021Updated 4 years ago
- ☆223Mar 11, 2023Updated 2 years ago
- Hide codes/data in the kernel address space.☆188May 8, 2021Updated 4 years ago
- Kill Protected Process Light Process (include av)☆58Sep 15, 2023Updated 2 years ago
- ☆39Oct 29, 2020Updated 5 years ago
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆219Nov 12, 2020Updated 5 years ago