Deputation / hygieiaLinks
Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.
☆146Updated 3 years ago
Alternatives and similar repositories for hygieia
Users that are interested in hygieia are comparing it to the libraries listed below
Sorting:
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆117Updated 3 years ago
- A simple tool to assemble shellcode ready to be copy-pasted into code☆68Updated 3 years ago
- ☆155Updated last year
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆85Updated 2 years ago
- nmi stackwalking + module verification☆131Updated last year
- Virtual and physical memory hacking library using gigabyte vulnerable driver☆71Updated 2 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆190Updated 2 years ago
- manually map driver for a signed driver memory space☆160Updated 4 years ago
- Some usefull info when reverse engineering Kernel Mode Anti-Cheat☆75Updated 2 years ago
- BattlEye shellcodes tester☆150Updated 3 years ago
- Kernel driver that uses Shared memory to communicate with UserMode☆89Updated 6 years ago
- Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode☆162Updated 3 years ago
- ☆129Updated 3 years ago
- bypass to the p2c(s) that I have run over the past few months.☆53Updated 2 years ago
- PE-Dump-Fixer☆111Updated 5 years ago
- base for testing☆173Updated 11 months ago
- Using CVE-2021-40449 to manual map kernel mode driver☆101Updated 3 years ago
- hidden_syscall - syscaller without using syscall instruction in code☆62Updated 2 years ago
- IoCreateDriver Implementation, it can be handful if you're trying to bypass anticheats☆100Updated 4 months ago
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆71Updated 5 years ago
- Unknowncheats Magically Optimized Tidy Mapper using nvaudio☆135Updated last year
- A simple ida python script to find .data ptr☆52Updated 2 years ago
- ☆153Updated 5 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆139Updated 3 years ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆96Updated 2 years ago
- ☆68Updated 4 years ago
- Discarded Section Manual Map☆68Updated 5 years ago
- Proof of concept on how to bypass some limitations of a manual mapped driver☆173Updated 4 years ago
- Obfuscate calls to imports by patching in stubs☆72Updated 4 years ago
- ☆147Updated 4 years ago