A Simple Example
☆23Nov 30, 2018Updated 7 years ago
Alternatives and similar repositories for KeUserModeCallBack
Users that are interested in KeUserModeCallBack are comparing it to the libraries listed below
Sorting:
- clearing traces of a loaded driver☆47Jul 2, 2022Updated 3 years ago
- ☆34Apr 11, 2023Updated 2 years ago
- ☆73Aug 31, 2022Updated 3 years ago
- Easy Anti PatchGuard☆223Apr 9, 2021Updated 4 years ago
- How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver☆26May 29, 2023Updated 2 years ago
- ☆12Oct 12, 2021Updated 4 years ago
- ☆17Jun 30, 2020Updated 5 years ago
- Stealing signatures from pe files☆15Apr 1, 2025Updated 11 months ago
- Debug Print viewer (user and kernel)☆72Feb 7, 2024Updated 2 years ago
- mash hypervisor host pml4☆17Jun 22, 2022Updated 3 years ago
- Experimental disassembler for x86 binaries virtualized by VMProtect 3☆98Aug 27, 2022Updated 3 years ago
- base for testing☆187Sep 28, 2024Updated last year
- An example code of CiGetCertPublisherName☆16Mar 24, 2022Updated 3 years ago
- This driver hooks a device object for ioctl and uses mdls to allocate physical pages and manually injects an entry into a process's page …☆15Feb 14, 2023Updated 3 years ago
- Detect removed thread from PspCidTable.☆75Mar 18, 2022Updated 4 years ago
- This project will give you an example how you can hook a kernel vtable function that cannot be directly called☆84Dec 25, 2021Updated 4 years ago
- Example of making debugger using Hardware Breakpoint + VEH☆18May 13, 2021Updated 4 years ago
- Simulate SendInput with ClassService☆35Sep 5, 2018Updated 7 years ago
- ☆23May 8, 2023Updated 2 years ago
- ☆26Aug 7, 2023Updated 2 years ago
- Static Library For Windows Drivers☆41Dec 13, 2025Updated 3 months ago
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆73Oct 29, 2019Updated 6 years ago
- POC usermode <=> kernel communication via ALPC.☆72Jun 6, 2024Updated last year
- ☆31Oct 1, 2021Updated 4 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆53Apr 7, 2022Updated 3 years ago
- Windows Minidump loader for Ghidra☆29Sep 30, 2022Updated 3 years ago
- Basic experimentation with Windows drivers.☆17Mar 3, 2023Updated 3 years ago
- ☆17Apr 21, 2022Updated 3 years ago
- ☆225Mar 11, 2023Updated 3 years ago
- ☆12Jun 30, 2019Updated 6 years ago
- A resource for thread hijacking and manual mapping code, that works with MEM_MAPPED & MEM_IMAGE.☆26Apr 17, 2021Updated 4 years ago
- Compileable POC of namazso's x64 return address spoofer.☆50Jun 10, 2020Updated 5 years ago
- Header only library for binding, reordering and currying of function arguments without cost☆17Jun 20, 2018Updated 7 years ago
- IO隐藏通信封装☆17May 31, 2021Updated 4 years ago
- Experiment to use sections as User/Kernelmode comm vector☆22Apr 7, 2023Updated 2 years ago
- Intercepting DeviceControl via WPP☆138Nov 18, 2019Updated 6 years ago
- NT reversal☆25Jul 12, 2018Updated 7 years ago
- ☆17Oct 31, 2022Updated 3 years ago
- A POC for Windows Extension Host hooking☆24Jul 13, 2019Updated 6 years ago