Lightweight Patchless Hooking Library for Windows
☆20Dec 31, 2025Updated 7 months ago
Alternatives and similar repositories for XATHook
Users that are interested in XATHook are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- https://github.com/janoglezcampos/c_syscalls with the ASM rewritten by myself for Visual Studio's Compiler.☆35Jun 23, 2024Updated 2 years ago
- A runtime Assembly dumper for powershell to combat the rise in .net based crypters and malware.☆18Aug 26, 2025Updated last year
- ☆33Oct 19, 2024Updated last year
- ☆11May 5, 2024Updated 2 years ago
- Utilizing DLang For Offensive Operations.☆15May 29, 2025Updated last year
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Near compile-time string obfuscation for Golang☆13Oct 3, 2023Updated 2 years ago
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated 11 months ago
- A tool to read and encrypt shellcode (.bin) and display encrypted bytes as output to be copied in Injectors for evasion☆16Dec 21, 2021Updated 4 years ago
- A simple Reset Survival PoC☆14Jan 25, 2026Updated 7 months ago
- HardwareTurningPoint, Fully Go Compatible Hardware Breakpoint☆15Jan 30, 2025Updated last year
- REcon 2024 Repo, slides for talk "GOP Complex: Image parsing bugs, EBC polymorphic engines and the Deus ex machina of UEFI exploit dev""☆14Mar 31, 2025Updated last year
- Shellcode capable of bypassing EAF / IAF mitigations☆30Apr 11, 2023Updated 3 years ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆141Aug 31, 2025Updated 11 months ago
- Spoof the return address of any function call.☆11Jul 21, 2024Updated 2 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Reversed WintaPix Malware Source code | That targets countries in the Middle East and abuse KeServiceDescriptorTable(SSDT), persistence a…☆21Jul 6, 2024Updated 2 years ago
- semi-auto static deobfuscator for functions which is obfuscated by lazy importer.☆16Nov 27, 2024Updated last year
- Reverse engineering malware samples☆16Dec 3, 2021Updated 4 years ago
- Python obfuscator with some cool features☆14Mar 19, 2025Updated last year
- Querying And Deleting Shadow Copies Using The IOCTL_VOLSNAP_QUERY_NAMES_OF_SNAPSHOTS & IOCTL_VOLSNAP_DELETE_SNAPSHOT IOCTLs☆22Aug 7, 2025Updated last year
- Undocumented MSVC☆50Nov 10, 2025Updated 9 months ago
- Shellcode encoder&loader written in Go language, which can encrypt binary or PE files. It offers a variety of complex encryption algorith…☆20May 24, 2024Updated 2 years ago
- golang decryption poc of the new app bound encryption introduced in chrome version 127.☆21Nov 4, 2024Updated last year
- A C++/Asm template for PIC/EXE/DLL malware☆24Aug 12, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A tool written in golang which compress using UPX and patch it with the provided PE file to make "UPX -d" flag impossible to decompress a…☆30Jan 2, 2025Updated last year
- Various novel EPT/NPT hook detection mechanisms.☆28Mar 20, 2026Updated 5 months ago
- A 64 bit executable junk code engine for polymorphic malware.☆79Jun 16, 2025Updated last year
- A slightly more fun way to disable windows defender☆53May 4, 2025Updated last year
- Perfect way to spoof SMBios serials before bootx64.efi ( UEFI )☆18May 14, 2025Updated last year
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated last year
- proper ntdll .text section unhooking via native api. unlike other unhookers this doesnt leave 2 ntdlls loaded. x86/x64/wow64 supported.☆55Dec 9, 2025Updated 8 months ago
- A helper class for hardware breakpoints☆12Apr 25, 2020Updated 6 years ago
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 5 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- use python on windows with full submodule support without installation☆31Jan 23, 2025Updated last year
- C++ Assembler with Built-in Mutation Engine☆31Sep 6, 2025Updated 11 months ago
- Hex-Rays Decompiler plugin for better code navigation. plugin for IDA Pro.☆28Nov 2, 2024Updated last year
- A runtime for developing large-scale and complex PIC module.☆21Updated this week
- async beacon object file for notification on process creation☆17Mar 24, 2026Updated 5 months ago
- dcsync bof☆54Feb 13, 2026Updated 6 months ago
- Intel.AES-NI: Leveraging Intel AES-NI for AES-128 & AES-256 Encryption Modes☆27Jun 10, 2025Updated last year