mouseclassservicecallback detection via hook
☆52Feb 7, 2022Updated 4 years ago
Alternatives and similar repositories for Detect-MouseClassServiceCallback
Users that are interested in Detect-MouseClassServiceCallback are comparing it to the libraries listed below
Sorting:
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆121Feb 8, 2022Updated 4 years ago
- Detect VM and Hypervisor☆10Jun 16, 2021Updated 4 years ago
- Detect removed thread from PspCidTable.☆75Mar 18, 2022Updated 3 years ago
- ☆15Oct 7, 2020Updated 5 years ago
- ☆158May 21, 2024Updated last year
- ☆23Oct 18, 2021Updated 4 years ago
- Old way for blocking NMI interrupts☆29Sep 6, 2022Updated 3 years ago
- ☆40Mar 23, 2023Updated 2 years ago
- Not mine. Only for saving☆26Jun 28, 2022Updated 3 years ago
- hooks gServerHandlers xxxEventWndProc☆13May 1, 2022Updated 3 years ago
- Hijack NotifyRoutine for a kernelmode thread☆41Jun 4, 2022Updated 3 years ago
- Cool kernel communication method.☆100Jun 27, 2021Updated 4 years ago
- Hide external overlay by using SetWindowDisplayAffinity☆102Sep 5, 2021Updated 4 years ago
- This project will give you an example how you can hook a kernel vtable function that cannot be directly called☆84Dec 25, 2021Updated 4 years ago
- neat way to detect memory read using nt layer function.☆14Aug 4, 2023Updated 2 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆107May 10, 2022Updated 3 years ago
- ☆34Apr 11, 2023Updated 2 years ago
- ☆47Nov 26, 2020Updated 5 years ago
- ☆84Apr 1, 2022Updated 3 years ago
- Intel learning hypervisor and some extend function☆23Aug 23, 2025Updated 6 months ago
- ☆19Apr 9, 2024Updated last year
- POC Hook of nt!HvcallCodeVa☆54May 8, 2023Updated 2 years ago
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆23Nov 22, 2021Updated 4 years ago
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆219Nov 12, 2020Updated 5 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆18Jan 15, 2022Updated 4 years ago
- partially disable patchguard up to win11 21H2☆19Jun 3, 2024Updated last year
- base for testing☆186Sep 28, 2024Updated last year
- Discarded Section Manual Map☆70Jun 18, 2020Updated 5 years ago
- ☆99Oct 6, 2017Updated 8 years ago
- Mapping your code on a 0x1000 size page☆71May 20, 2022Updated 3 years ago
- A C++ syscall ID extractor for Windows. Developed, debugged and tested on 20H2.☆21May 25, 2021Updated 4 years ago
- Windows system spy for Mouse, Keyboard and Gamepad(Joystick).☆15Jul 6, 2022Updated 3 years ago
- pdb's function and global vars to offset☆10Apr 11, 2023Updated 2 years ago
- If you made it in here I have no clue how, well hi☆13Apr 10, 2022Updated 3 years ago
- fix wow obfucated IAT☆10Aug 4, 2021Updated 4 years ago
- Medal.tv Hook / D3D Present & ResizeBuffers Hook☆22Oct 3, 2022Updated 3 years ago
- ☆18Dec 4, 2020Updated 5 years ago
- An x64 page table iterator written in C++ as a kernel mode windows driver.☆119May 25, 2021Updated 4 years ago
- UEDumper☆44Apr 13, 2021Updated 4 years ago