ExpLife0011 / KeUserModeCallBack
A Simple Example
☆20Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for KeUserModeCallBack
- A poc that abuses Enclave☆36Updated 2 years ago
- ☆33Updated 4 years ago
- ☆28Updated last year
- ☆29Updated last year
- ☆70Updated 2 years ago
- UM-KM Communication using registry callbacks☆39Updated 4 years ago
- comparing data of module exports from disk and memory, then caching any differences.☆22Updated 2 years ago
- Illustrates the concept of return address spoofing, and how it is used.☆14Updated 4 years ago
- search for a driver/dll module that has a wanted section bigger than the size of your image☆20Updated 3 years ago
- Register a callback in Kernel from a manually mapped driver☆37Updated 3 years ago
- Old way for blocking NMI interrupts☆25Updated 2 years ago
- ☆14Updated 3 years ago
- C/C++ example of InjectMouseInput function☆31Updated 3 years ago
- Handling C++ & __try exceptions without the need of built-in handlers.☆65Updated 3 years ago
- A minimalistic way to spoof return addresses without using exceptions☆14Updated 2 years ago
- Mapping your code on a 0x1000 size page☆69Updated 2 years ago
- fecurity executor from factory☆33Updated 2 years ago
- 将驱动映射到会话空间☆33Updated 2 years ago
- ☆18Updated 2 years ago
- Detect removed thread from PspCidTable.☆68Updated 2 years ago
- detect hypervisor with Nmi Callback☆34Updated 2 years ago
- A wrapper class to hide the original calling address of a function☆55Updated 4 years ago
- PsSetCreateProcessNotifyRoutine bypass proof-of-concept for manual mapped drivers☆31Updated 3 years ago
- Windows Kernel nt files - To research windows kernel☆15Updated 4 years ago
- ☆26Updated 2 years ago