Dabudabot / injection-monitor
Kernel based monitor to check if specified process loads libraries only from allowed directories
☆12Updated 4 years ago
Alternatives and similar repositories for injection-monitor:
Users that are interested in injection-monitor are comparing it to the libraries listed below
- ☆11Updated 4 years ago
- Demonstrate the new FileDispositionInfoEx behavior☆14Updated 7 years ago
- A tool to investigate the Windows device manager☆14Updated 6 years ago
- SoftICE-like debugger for Windows 2000 and XP. Archived.☆17Updated 2 years ago
- WoW64 -> x64☆19Updated 8 years ago
- UAC bypass and Elevate☆13Updated 8 years ago
- File downloader with SSL support and progress bar☆19Updated 7 years ago
- Dump PDB Symbols including support for Bochs Debugging Format (with wine support)☆15Updated last year
- a demo for x86/x64's paging memory management learning, convert a virtual address from ring3 to physical address in ring0☆17Updated 7 years ago
- ☆33Updated 4 years ago
- Basic experimentation with Windows drivers.☆14Updated 2 years ago
- Simple utility to watch directory change notifications on a given path☆17Updated 7 years ago
- ☆28Updated 4 years ago
- An open source library for operating the Windows Overlay Filter driver.☆22Updated 6 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆25Updated 10 years ago
- Basic utilities for executing, reading and writing 64-bit data in a 32-bit WoW64 process☆17Updated 2 years ago
- reveal and detect of common hooks under win32☆13Updated 4 years ago
- use crystalCPUID to identify vt-x & amd-v☆16Updated 10 years ago
- ☆13Updated 6 years ago
- ☆9Updated 11 years ago
- ☆14Updated 12 years ago
- Library for using direct system calls☆35Updated 2 months ago
- Ready-to-use headers for Windows Kernel SSDT indices☆11Updated 5 years ago
- A Hobbyist Operating System based off the ReactOS/NT Kernel experimenting with OS Development.☆26Updated 12 years ago
- use ce driver, kernel library.☆14Updated 2 years ago
- PE Infector/Cryptor source code☆15Updated 7 years ago
- A driverless driver that is supposed to be manually mapped, usually by using TDL exploit. The driver shows how to read/write to any proce…☆21Updated 7 years ago
- Low-level MS Windows registry files analysis tools☆20Updated 8 years ago
- Proof of concept headless GUI DLL☆12Updated 3 years ago
- Full reversing of the Microsoft Auxiliary Windows API Library and ported to C☆23Updated 4 months ago