A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.
☆166Nov 14, 2021Updated 4 years ago
Alternatives and similar repositories for instrumentation_callbacks
Users that are interested in instrumentation_callbacks are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An x64 page table iterator written in C++ as a kernel mode windows driver.☆123May 25, 2021Updated 5 years ago
- A C++ syscall ID extractor for Windows. Developed, debugged and tested on 20H2.☆22May 25, 2021Updated 5 years ago
- Illustrates the concept of return address spoofing, and how it is used.☆14May 13, 2020Updated 6 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆201Jul 11, 2023Updated 3 years ago
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆70Oct 29, 2019Updated 6 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- ☆158May 21, 2024Updated 2 years ago
- A simple way to spoof return addresses using an exception handler☆42Aug 3, 2022Updated 4 years ago
- This tool will allow you to spoof the return addresses of your functions as well as system functions.☆582Nov 12, 2022Updated 3 years ago
- mouseclassservicecallback detection via hook☆53Feb 7, 2022Updated 4 years ago
- Walks through the 4-level paging structures in Windows x64☆14Feb 12, 2023Updated 3 years ago
- BattlEye shellcodes tester☆155Jan 3, 2022Updated 4 years ago
- ☆191Dec 8, 2021Updated 4 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆103May 10, 2022Updated 4 years ago
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆154Feb 12, 2022Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- This program remaps its image to prevent the page protection of pages contained in the image from being modified via NtProtectVirtualMemo…☆637Mar 19, 2019Updated 7 years ago
- Allows you to communicate with the kernel mode to manipulate memory in a stealthy way to avoid kernel anticheats.☆172May 8, 2022Updated 4 years ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆117Feb 8, 2022Updated 4 years ago
- 09/2021 reversal of EasyAntiCheat driver☆244Dec 21, 2021Updated 4 years ago
- nmi stackwalking + module verification☆176Dec 28, 2023Updated 2 years ago
- Handling C++ & __try exceptions without the need of built-in handlers.☆77Aug 28, 2021Updated 5 years ago
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆220Nov 12, 2020Updated 5 years ago
- 🪝 Various EPT hook detection approaches☆157Feb 22, 2026Updated 6 months ago
- ☆86Apr 1, 2022Updated 4 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- base for testing☆197Sep 28, 2024Updated last year
- Emulate Drivers in RING3 with self context mapping or unicorn☆387Aug 18, 2022Updated 4 years ago
- Code for Battleyes shellcode☆233Nov 11, 2021Updated 4 years ago
- UM-KM Communication using registry callbacks☆39Jun 8, 2020Updated 6 years ago
- A simple example how to decrypt kernel debugger data block☆32Feb 8, 2021Updated 5 years ago
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆23Nov 22, 2021Updated 4 years ago
- Enumerate various traits from Windows processes as an aid to threat hunting☆198Jan 13, 2022Updated 4 years ago
- InfinityHookPro Win7 -> Win11 latest☆564Feb 7, 2023Updated 3 years ago
- The Grimoire Hypervisor solution for x86 Processors with experimental nested virtualization support. Remastering with Rust in progress.☆653Sep 5, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆422Jul 6, 2022Updated 4 years ago
- Easily hook WIN32 x64 functions☆18Feb 19, 2025Updated last year
- A mapper that maps shellcode into loaded large page drivers☆368Apr 26, 2022Updated 4 years ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆678Jan 28, 2025Updated last year
- Bypassing EasyAntiCheat.sys self-integrity by abusing call hierarchy☆81Oct 6, 2022Updated 3 years ago
- PAGE_GUARD based hooking library☆53Jul 25, 2022Updated 4 years ago
- Finding Truth in the Shadows☆127Jan 26, 2023Updated 3 years ago