FiYHer / system_trace_tool
内核驱动加载/卸载痕迹清理,努力绕过反作弊吧 PiDDBCacheTable and MmLastUnloadedDriver
☆140Updated last year
Related projects ⓘ
Alternatives and complementary repositories for system_trace_tool
- ☆171Updated last year
- 句柄提权 无视反作弊读写游戏内存 用于分析游戏结构工具☆134Updated 3 years ago
- 从MmPfnData中枚举进程和页目录基址☆138Updated last year
- ☆142Updated 2 years ago
- 驱动加载器 -> 利用iqvw64e.sys映射驱动☆49Updated 4 years ago
- ShotHv☆125Updated 2 years ago
- ☆49Updated last year
- Hide Process☆52Updated 4 months ago
- ☆159Updated 2 years ago
- A Memory Read And Write the Hide Driver☆63Updated 3 years ago
- VT DEBUGGER☆49Updated last year
- r/w virtual memory without attach☆152Updated last year
- 轻量级VT框架和Ept无痕HOOK,测试环境:WIN10 1903,WIN7☆138Updated 2 years ago
- Kernel dwm render☆127Updated last year
- A very simple C++ library for download pdb, get rva of function, global variable and offset from struct.☆111Updated 7 months ago
- ☆30Updated last month
- 远程注入无导入函数dll,自动重定位以后内存加载dll☆43Updated 5 years ago
- InjectDll☆53Updated 6 years ago
- Example of reading process memory through kernel special APC☆98Updated last year
- 利用CE的DBK驱动加载未签名驱动☆25Updated last year
- a monitoring windows driver calls kernel api tools☆94Updated 4 months ago
- etw hook (syscall/infinity hook) compatible with the latest Windows version of PG☆212Updated 6 months ago
- Use RTCore64 to map your driver on windows 11.☆93Updated 7 months ago
- ☆80Updated 2 years ago
- This project can bypass most of the AC except for some perverts that enable VT to monitor page tables☆39Updated 6 months ago
- 不使用3环挂钩进行DWM桌面绘制☆78Updated 2 years ago
- 内核级别隐藏指定窗口☆50Updated 2 years ago
- InfinityHook 支持Win7 到 Win11 最新版本,虚拟机环境及物理机环境☆34Updated last month
- Quick check of NT kernel exported&unexported functions/global variable offset NT内核导出以及未导出函数+全局变量偏移速查☆91Updated last year