[Windows Anti-Rootkit] KSword 5.1 is an source-available Windows toolkit for ARK, kernel debugging, and system forensics. KSword 5.1 是面向 Windows 的源码可见 ARK、内核调试与系统取证工具集。
☆522Oct 9, 2026Updated this week
Alternatives and similar repositories for KSword
Users that are interested in KSword are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Anti-Rootkit & System kernel management tool☆84Jun 30, 2026Updated 3 months ago
- 一个强大而易用的 Windows 内核级工具箱,使用 C++/WinRT WinUI3 编写☆441Aug 23, 2026Updated last month
- 内核驱动加载/卸载痕迹清理,努力绕过反作弊吧 PiDDBCacheTable and MmLastUnloadedDriver☆190Feb 11, 2023Updated 3 years ago
- An IDA Pro plugin that simulate time-travel debugging by emulating code execution with Unicorn.☆42Jul 30, 2025Updated last year
- a monitoring windows driver calls kernel api tools☆141Jul 5, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Radical Windows ARK☆255Apr 18, 2025Updated last year
- 硬件虚拟化☆64Aug 13, 2025Updated last year
- Imgui Menu for Games☆11Feb 23, 2025Updated last year
- memory introspection and reverse engineering hypervisor powered by leveraging Hyper-V☆796Jul 24, 2026Updated 2 months ago
- Windows Anti-Rootkit Tool☆576Jul 25, 2026Updated 2 months ago
- 黑客项目_Qt框架和现代C++从0开始重写CheatEngine应用层,通过kdmapper手动映射DBK驱动,并重构DBK与Cheat Engine的通讯机制,绕过微软签名☆121May 20, 2026Updated 4 months ago
- Lightweight, dependency-free x86-64 CPU emulation library with Unicorn-like guest mode and direct host-memory execution.☆235May 11, 2026Updated 4 months ago
- InfinityHook 支持Win7 到 Win11 最新版本,虚拟机环境及物理机环境☆125May 20, 2026Updated 4 months ago
- Windows kernel-mode reboot-restore driver — NTFS volume filter with copy-on-write redirection☆64Jun 11, 2026Updated 3 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Bypass protection and hide CE via VT-x hypervisor and ept hook to use cheat engine .☆234Jan 2, 2025Updated last year
- ☆15Apr 8, 2026Updated 6 months ago
- Kernel dwm render☆178Oct 10, 2023Updated 2 years ago
- 授权搬运,作者QQ2907783620☆22Apr 8, 2026Updated 6 months ago
- 巨硬☆18Oct 4, 2023Updated 3 years ago
- A Kernel Driver that can be used for a cheat or malware base to circumvent common cache & structure table checks. PsLoadedModuleList howe…☆225Apr 23, 2026Updated 5 months ago
- Kernel driver that .text hooks a syscall in dxgkrnl.sys which can be called from our user-mode client to send instructions like rpm/wpm a…☆238Dec 16, 2022Updated 3 years ago
- 使用 Intel 虚拟化特性实现应用层HOOK☆66Sep 11, 2025Updated last year
- 可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。☆108Sep 1, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- VMPilot: A Modern C++ Virtual Machine SDK☆306Apr 24, 2026Updated 5 months ago
- A remote control program: 基于NetBot的远程控制程序:具备在线主机维护、DDOS、文件管理、屏幕监控、Shell终端、参数配置和服务生成等功能。项目代码仅限于学习和交流用途。☆16Feb 4, 2025Updated last year
- r/w virtual memory without attach☆233Oct 19, 2023Updated 2 years ago
- Windows Kernel Security: Memory Integrity Verification with Disk Verification of ntoskrnl.exe☆28Mar 23, 2025Updated last year
- The first Computer Emergency Response (ARK) Tools for young people ;) 年轻人的第一款应急响应(ARK)工具 ;)☆688Oct 21, 2025Updated 11 months ago
- Example of reading process memory through kernel special APC☆111Apr 21, 2023Updated 3 years ago
- Modern PE/ARM/.NET analyzer and editor rebuilt with Qt 5.15☆51May 4, 2026Updated 5 months ago
- Windows 11 kernel research framework demonstrating DSE bypass on Windows 11 25H2 through boot-time execution. Loads unsigned drivers by s…☆277Apr 9, 2026Updated 6 months ago
- 一个windows内核驱动分析框架,对内核所有导出函数进行挂钩监控☆77Nov 19, 2025Updated 10 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- 自建时间戳服务器实现伪签名驱动证书 Implementing Pseudo Signature with Self-Sign Timestamp Servers☆532May 26, 2026Updated 4 months ago
- A hybrid Windows endpoint security platform powered by machine learning, YARA rules, cloud analysis, and kernel-level behavioral protecti…☆566Updated this week
- Browse Page Tables on Windows (Page Table Viewer)☆242Apr 2, 2022Updated 4 years ago
- A Windows Kernel Driver Emulator base on Unicorn, Kernel Memory Dump and some of native environment☆202Aug 27, 2026Updated last month
- ☆29Aug 22, 2026Updated last month
- POC for CVE-2023-29360☆11Aug 31, 2024Updated 2 years ago
- Visual Studio 2019/2022/2026 extension for building C/C++ projects with the LLVM Compiler Toolchain (installed separately).☆26May 16, 2026Updated 4 months ago