Registers Vectored Exception Handlers by directly manipulating internal LdrpVectorHandlerList structure instead of calling RtlAddVectoredExceptionHandler.
☆35Jan 18, 2026Updated 2 months ago
Alternatives and similar repositories for GhostVEH
Users that are interested in GhostVEH are comparing it to the libraries listed below
Sorting:
- C++ Assembler with Built-in Mutation Engine☆30Sep 6, 2025Updated 6 months ago
- Cobaltstrike UDRL with memory evasion☆15May 16, 2024Updated last year
- Vectored Exception Handling Squared☆31Dec 27, 2025Updated 2 months ago
- sigreturn-oriented programming (SROP) based sleep obfuscation poc for Linux☆68Dec 15, 2025Updated 3 months ago
- Linux Shared Library to Shellcode Loader☆88Feb 15, 2026Updated last month
- A Windows Kernel Driver Emulator base on Unicorn, Kernel Memory Dump and some of native environment☆165Jan 15, 2026Updated 2 months ago
- mash hypervisor host pml4☆17Jun 22, 2022Updated 3 years ago
- Minimalistic HTTP(S) client for the NT kernel☆62Dec 1, 2025Updated 3 months ago
- Linux Process Injection via Seccomp Notifier☆84Dec 9, 2025Updated 3 months ago
- A C++ wrapper for icedx86 decoder☆48Jul 28, 2025Updated 7 months ago
- Extracted lua script from Defender mpavbase.vdm and mpasbase.vdm☆16Jul 5, 2024Updated last year
- A Windows C++ OLE/COM Object explorer written in WTL.☆16Feb 28, 2025Updated last year
- Hotkey-based keylogger for Windows☆33Oct 17, 2024Updated last year
- Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088☆55Aug 18, 2025Updated 7 months ago
- reverse engineering random malwares☆22Updated this week
- PsSetCreateProcessNotifyRoutine/Ex/Ex2 hook☆13May 30, 2024Updated last year
- Detect BypassUAC using AMSI☆29Feb 18, 2025Updated last year
- ☆38Oct 16, 2025Updated 5 months ago
- Proof-of-Concept to evade auditd by tampering via ptrace☆19Aug 3, 2023Updated 2 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆202Jul 11, 2023Updated 2 years ago
- ☆37Nov 8, 2024Updated last year
- Using the peculiar behaviour of the VPGATHER instructions to determine if an address will fault before it is truly accessed. All done in …☆55Dec 30, 2025Updated 2 months ago
- x86-x64 Packer with Portable Executable compatibility.☆101Dec 15, 2025Updated 3 months ago
- Golang bindings for the Binary Ninja Arm64 Disassembler.☆14Mar 10, 2026Updated last week
- 内存加载执行golang elf二进制文件☆29Dec 22, 2021Updated 4 years ago
- ☆29Dec 29, 2022Updated 3 years ago
- ☆37Feb 12, 2026Updated last month
- fork HoShiMin Avanguard☆20Sep 29, 2018Updated 7 years ago
- Eset-Unload is a C++ tool that interacts with a process's loaded modules to identify and unload the ebehmoni.dll module, typically found …☆12Apr 21, 2025Updated 10 months ago
- MeowTools - maybe some useful tools for CTFers / programmers☆20Nov 27, 2022Updated 3 years ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆79Aug 25, 2025Updated 6 months ago
- Kernel Level NMI Callback Blocker☆167Sep 27, 2025Updated 5 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆139Aug 25, 2025Updated 6 months ago
- simple trampoline hooking PoC☆14Nov 8, 2023Updated 2 years ago
- A basic implementation of Patch Guard that I implemented, that includes integrity checks and other protection mechanisms I added.☆78Mar 29, 2025Updated 11 months ago
- A lightweight Windows Prefetch file parser to extract programs' execution history☆68Jan 12, 2026Updated 2 months ago
- Finding Truth in the Shadows☆124Jan 26, 2023Updated 3 years ago
- Loads NTDLL, parses the PE file, extracts "Zw" functions, retrieves their System Service Numbers (SSNs), and prints each function’s name,…☆15Apr 21, 2025Updated 10 months ago
- api-tracer is a tiny (useless) tracer☆17Feb 28, 2023Updated 3 years ago