Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.
☆82Jan 24, 2011Updated 15 years ago
Alternatives and similar repositories for PTBypass-PoC
Users that are interested in PTBypass-PoC are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Hidden kernel mode code execution for bypassing modern anti-rootkits.☆84Dec 23, 2010Updated 15 years ago
- Simple tool for unpacking packed/protected malware executables.☆32Oct 27, 2011Updated 14 years ago
- An analytical debugger programmed in C++, using Qt.☆22May 20, 2012Updated 14 years ago
- A kernel level anti-rootkit tool which runs on the windows platform.☆91Apr 18, 2014Updated 12 years ago
- ☆10Sep 29, 2019Updated 6 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Notes my learning steps about Windows-NT☆23May 18, 2017Updated 9 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆79Aug 12, 2015Updated 10 years ago
- The dll that can hide itself and then delete itselft.☆33Mar 31, 2013Updated 13 years ago
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆32Mar 22, 2017Updated 9 years ago
- Windows kernel-mode callbacks tutorial driver☆46Aug 8, 2016Updated 9 years ago
- windows kernel File redirection☆20Sep 21, 2014Updated 11 years ago
- A C/C++ code obfuscator based on llvm/clang technology☆16Sep 19, 2014Updated 11 years ago
- ☆19Jul 20, 2015Updated 11 years ago
- Kinject - kernel dll injector, currently available in x86 version, will be updated to x64 soon.☆32Apr 10, 2015Updated 11 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- hypervisor in windows device driver by intel vt☆14Aug 25, 2018Updated 7 years ago
- Minifilter Driver☆15Feb 10, 2017Updated 9 years ago
- A simple tool to help reverse engineers while dealing with obfuscated code.☆20Sep 5, 2016Updated 9 years ago
- Today Plugin (x64) - A Plugin For x64dbg☆13Jul 17, 2018Updated 8 years ago
- ☆14Mar 13, 2023Updated 3 years ago
- codes for my blog post: https://secrary.com/Random/InstrumentationCallback/☆180Nov 30, 2017Updated 8 years ago
- Windows Kernel Mode PCRE☆10Feb 4, 2015Updated 11 years ago
- ☆14Jan 10, 2017Updated 9 years ago
- The Network project is a C++ encapsulation of WinSock2 to form a lightweight network library; The Graphics project is a C++ encapsulation…☆13Oct 31, 2017Updated 8 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A system call tracer☆10Sep 22, 2014Updated 11 years ago
- analyze the content of the pe file on windows, and shell(pack) function for windows drivers.☆11Nov 9, 2018Updated 7 years ago
- ☆30May 23, 2017Updated 9 years ago
- Obtain remote process cookies by performing a brute-force attack on ntdll.RtlDecodePointer using known pointer encodings.☆23May 31, 2017Updated 9 years ago
- Modify process handle permissions☆60Nov 30, 2016Updated 9 years ago
- PE/PE +(64bit) Viewer (Qt 5.8)☆10Aug 3, 2018Updated 7 years ago
- RootKit & Cheat Scanner - Windows☆225Aug 9, 2019Updated 6 years ago
- Common Malware Techniques☆13Mar 26, 2023Updated 3 years ago
- Decompile an x86 exe, and read PE infos.☆19Sep 29, 2018Updated 7 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- A sample project for using Capstone from a driver in Visual Studio 2015☆37May 4, 2016Updated 10 years ago
- A sample on how to inject a DLL from a kernel driver☆62Sep 13, 2016Updated 9 years ago
- Wow64 syscall hook☆43May 28, 2017Updated 9 years ago
- ☆84Dec 3, 2017Updated 8 years ago
- Simple proof of concept code for injecting libraries on 64bit processes from a 32bit process☆96Oct 12, 2018Updated 7 years ago
- Windows PE file debugger☆11Aug 30, 2017Updated 8 years ago
- Kernel mode driver loader, injecting into the windows kernel, Rootkit. Driver injections.☆47Nov 9, 2014Updated 11 years ago