Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.
☆118Feb 8, 2022Updated 4 years ago
Alternatives and similar repositories for Detect-KeAttachProcess
Users that are interested in Detect-KeAttachProcess are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Mapping your code on a 0x1000 size page☆70May 20, 2022Updated 4 years ago
- mouseclassservicecallback detection via hook☆53Feb 7, 2022Updated 4 years ago
- Easy Anti PatchGuard☆219Apr 9, 2021Updated 5 years ago
- ☆46Feb 27, 2022Updated 4 years ago
- Hiding the window from screenshots using the function win32kfull::GreProtectSpriteContent☆648Dec 26, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆157May 21, 2024Updated 2 years ago
- Old way for blocking NMI interrupts☆28Sep 6, 2022Updated 3 years ago
- Code for Battleyes shellcode☆237Nov 11, 2021Updated 4 years ago
- hooks gServerHandlers xxxEventWndProc☆12May 1, 2022Updated 4 years ago
- ☆192Dec 8, 2021Updated 4 years ago
- Bypassing EasyAntiCheat.sys self-integrity by abusing call hierarchy☆81Oct 6, 2022Updated 3 years ago
- An example code of CiGetCertPublisherName☆15Mar 24, 2022Updated 4 years ago
- Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode☆161Jul 31, 2022Updated 3 years ago
- Using SetWindowHookEx for preinjected DLL's☆58Aug 25, 2022Updated 3 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- base for testing☆193Sep 28, 2024Updated last year
- ☆143Dec 10, 2022Updated 3 years ago
- PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and pre…☆58May 23, 2022Updated 4 years ago
- Discarded Section Manual Map☆68Jun 18, 2020Updated 6 years ago
- This project will give you an example how you can hook a kernel vtable function that cannot be directly called☆81Dec 25, 2021Updated 4 years ago
- UD overlay using SetWindowsHookEx☆16Apr 29, 2022Updated 4 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆370Aug 18, 2022Updated 3 years ago
- Hijack NotifyRoutine for a kernelmode thread☆38Jun 4, 2022Updated 4 years ago
- InfinityHookPro Win7 -> Win11 latest☆556Feb 7, 2023Updated 3 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- 09/2021 reversal of EasyAntiCheat driver☆246Dec 21, 2021Updated 4 years ago
- ☆47Mar 29, 2022Updated 4 years ago
- An x64 page table iterator written in C++ as a kernel mode windows driver.☆123May 25, 2021Updated 5 years ago
- Example of reading process memory through kernel special APC☆111Apr 21, 2023Updated 3 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆105May 10, 2022Updated 4 years ago
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆151Feb 12, 2022Updated 4 years ago
- Rendering on external windows via hijacking thread contexts☆403Jun 28, 2020Updated 6 years ago
- ☆50Dec 19, 2023Updated 2 years ago
- Using CVE-2021-40449 to manual map kernel mode driver☆103Mar 5, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Disks for DMA☆159Apr 28, 2021Updated 5 years ago
- ☆105Mar 26, 2022Updated 4 years ago
- c++ implementation of windows heavens gate☆70Feb 12, 2021Updated 5 years ago
- ☆135Aug 6, 2022Updated 3 years ago
- Loads a signed kernel driver which allows you to map any driver to kernel mode without any traces of the signed / mapped driver.☆407Aug 8, 2021Updated 4 years ago
- ☆86Apr 1, 2022Updated 4 years ago
- ☆221May 10, 2022Updated 4 years ago