FiYHer / driver_callback_bypass_1909
研究和移除各种内核回调,在anti anti cheat的路上越走越远
☆167Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for driver_callback_bypass_1909
- Quick check of NT kernel exported&unexported functions/global variable offset NT内核导出以及未导出函数+全局变量偏移速查☆91Updated last year
- 无痕注入1☆69Updated 3 years ago
- 从MmPfnData中枚举进程和页目录基址☆139Updated last year
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆201Updated 4 years ago
- 利用物理内存映射,实现虚拟内存的伪隐藏☆73Updated 2 years ago
- 不 使用3环挂钩进行DWM桌面绘制☆78Updated 2 years ago
- ☆171Updated last year
- ☆108Updated 5 years ago
- 让Etwhook再次伟大! Make InfinityHook Great Again!☆124Updated 3 years ago
- 内核驱动加载/卸载痕迹清理,努力绕过反作弊吧 PiDDBCacheTable and MmLastUnloadedDriver☆140Updated last year
- 驱动加载器 -> 利用iqvw64e.sys映射驱动☆49Updated 4 years ago
- ShotHv☆126Updated 2 years ago
- shellcode 生成框架☆240Updated 2 years ago
- 滥用cow机制进行全局注入☆91Updated 3 years ago
- 隐藏可执行内存☆245Updated 9 months ago
- 可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。☆104Updated 2 years ago
- 远程注入无导入函数dll,自动重定位以后内存加载dll☆43Updated 5 years ago
- ☆159Updated 2 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆101Updated 2 years ago
- Example of reading process memory through kernel special APC☆98Updated last year
- 内核级别隐藏指定窗口☆297Updated 2 years ago
- Use RTCore64 to map your driver on windows 11.☆93Updated 7 months ago
- ☆69Updated 2 years ago
- query-pdb is a server-side software for parsing PDB files. The software provides PDB online parsing service.☆140Updated 2 months ago
- InfinityHook 支持Win7 到 Win11 最新版本,虚拟机环境及物理机环境☆34Updated last month
- CVE-2022-3699 with arbitrary kernel code execution capability☆70Updated last year
- 内核级别隐藏指定窗口☆50Updated 2 years ago
- 之前学习X64VT写的代码,很多坑,但是大体的逻辑还是完整的。现发出来给更多想学VT的人参考...☆66Updated 3 years ago
- Unknowncheats Magically Optimized Tidy Mapper using nvaudio☆100Updated 5 months ago
- ☆80Updated 2 years ago