HoneProject / Windows-SensorLinks
Perform packet-process correlation on Windows using the Windows equivalent of the Linux sensor.
☆25Updated 10 years ago
Alternatives and similar repositories for Windows-Sensor
Users that are interested in Windows-Sensor are comparing it to the libraries listed below
Sorting:
- Anti-Anti-VM solution via Windows Driver☆62Updated 7 years ago
- OpenSrc projects; common multiprojects headers store to ./Common/*category*/☆51Updated 11 years ago
- Windows Kernel Driver - Create a driver device in TDI layer of windows kernel to capture network data packets☆37Updated 11 years ago
- ☆21Updated 10 years ago
- just an lite AntiRootkit for interesting☆24Updated 10 years ago
- Helper utility for debugging windows PE/PE+ loader.☆52Updated 10 years ago
- Open Source Libraries Collection☆24Updated 9 years ago
- Windows anti-rootkit library☆36Updated 10 years ago
- Elevation of privilege detector based on HyperPlatform☆123Updated 8 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆57Updated 9 years ago
- drvtriks kernel driver for Windows 7 SP1 and 8.1 x64, that tricks around in your system.☆33Updated 8 years ago
- A command tree based on commands and extensions for Windows Kernel Debugging.☆109Updated 5 years ago
- WinDbg debugger extension library providing various tools to analyse, dump and fix (restore) Microsoft Portable Executable files for both…☆84Updated last year
- A minifilter driver preserves all modified and deleted files.☆80Updated 10 years ago
- Library for kernel and user mode splicing for Windows (x86 and x64).☆64Updated 13 years ago
- Simple code generation library developed in C intended for code generation in Kernel mode☆17Updated 3 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆79Updated 10 years ago
- nyā☆69Updated 10 years ago
- Simple standalone bundle of NT core APIs☆25Updated 9 years ago
- Windows kernel-mode callbacks tutorial driver☆47Updated 9 years ago
- ☆12Updated 9 years ago
- Windbg extension to find PatchGuard pages☆123Updated 11 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆78Updated 14 years ago
- Decrement Windows Kernel for fun and profit☆38Updated 7 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆58Updated 7 years ago
- Simple proof of concept code for injecting libraries on 64bit processes from a 32bit process☆96Updated 7 years ago
- Shareds for kernel developement☆28Updated 11 years ago
- POC of sysenter x64 LSTAR MSR hook☆40Updated 11 years ago
- Hidden kernel mode code execution for bypassing modern anti-rootkits.☆85Updated 14 years ago
- A-Protect Anti Rootkit Tool☆54Updated 11 years ago