DavidXanatos / HideTS
DLL and API hooking example to hide running in a Terminal Session
☆18Updated 4 years ago
Alternatives and similar repositories for HideTS
Users that are interested in HideTS are comparing it to the libraries listed below
Sorting:
- Windows x86 Hardware Breakpoint class for Windows >Vista☆22Updated 8 years ago
- A small library to extend the functionality of GetModuleHandle and GetProcAddress to other processes☆17Updated 5 years ago
- Input-output driver☆26Updated 2 months ago
- Demonstrate the new FileDispositionInfoEx behavior☆14Updated 7 years ago
- Small class to help perform syscalls.☆21Updated 2 weeks ago
- ☆20Updated 5 years ago
- Debugger checks in 3 ways☆19Updated 7 years ago
- Proof of concept headless GUI DLL☆12Updated 3 years ago
- ☆10Updated 4 years ago
- A small utility to run raw code chunks in the executable memory area.☆14Updated 10 years ago
- Given a global name in IDA Pro, find all xrefs which are contained in an exported function.☆11Updated 8 years ago
- Simple library to handle PE files loading, relocating, get/set data, ..., in addition to process handling☆33Updated 5 years ago
- A tool to investigate the Windows device manager☆14Updated 6 years ago
- A class to gather information about a process, its threads and modules.☆24Updated 5 years ago
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- Analysis and Modification Tool for Executables☆16Updated 6 years ago
- Diff plugin for x64dbg☆31Updated 4 years ago
- x64dbg scripts for finding OEP of packers☆14Updated 6 years ago
- Remote memory library in C++17.☆31Updated 6 years ago
- Simple command line version of Sysinternals WinObj. Currently just lists object names and types given an object manager directory.☆20Updated last year
- x64 injector using LoadLibrary made in assembler (MASM)☆26Updated 6 years ago
- Code Injection technique written in cpp language☆31Updated 7 years ago
- Windows hidden thread suspend POC with code injection☆12Updated 7 years ago
- Small project to generate fake DLLs based on an executable's import table☆23Updated 5 years ago
- INF Studio for easier working with driver installation files☆37Updated last year
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆26Updated 6 years ago
- Undocumented way of fetching list of processes by bruteforcing NtQuerySystemInformation☆16Updated 7 years ago
- Taking advantage of CRT initialization, to get away with hooking protected applications☆46Updated 2 years ago
- Simple x64dbg plugin to show registers on every step.☆16Updated 5 years ago
- Simple error lookup for Win32 and NTSTATUS errors☆19Updated 6 years ago