Luiz-Monad / papersLinks
☆18Updated 5 years ago
Alternatives and similar repositories for papers
Users that are interested in papers are comparing it to the libraries listed below
Sorting:
- Windows PDB parser for kernel-mode environment.☆104Updated 8 months ago
- intel vt-x type 2 hypervisor☆61Updated 9 months ago
- Kernel ReClassEx☆66Updated 2 years ago
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆79Updated 3 years ago
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆60Updated last year
- Test data for x86 instructions☆13Updated 4 years ago
- Hijacking Hyper-V at Runtime with DDMA☆76Updated 5 months ago
- x64 PE-COFF virtualization driven obfuscation engine☆58Updated 3 years ago
- Visual Studio Project example for using Microsoft's STL in WDM (Windows Kernel-mode Driver)☆25Updated 4 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆18Updated 4 years ago
- Integration of Microsoft Warbird with the MSVC compiler☆127Updated 2 years ago
- devirtualization vmprotect☆65Updated 2 years ago
- A devirtualization engine for Themida.☆106Updated last year
- This is a ring -1 header framework in order to simplify the creation of hypervisors on SVM☆27Updated 2 years ago
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆51Updated 4 years ago
- A native Windows library for intercepting kernel-to-user transitions using instrumentation callbacks☆28Updated 2 years ago
- Binary rewriter for 64-bit PE files.☆99Updated 2 years ago
- A simple way to spoof return addresses using an exception handler☆43Updated 3 years ago
- vdk is a set of utilities used to help with exploitation of a vulnerable driver.☆46Updated 3 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆53Updated 3 years ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆71Updated 3 years ago
- This driver hooks a device object for ioctl and uses mdls to allocate physical pages and manually injects an entry into a process's page …☆15Updated 2 years ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆50Updated 2 years ago
- Another UEFI runtime bootkit☆36Updated 2 years ago
- POC Hook of nt!HvcallCodeVa☆54Updated 2 years ago
- Collection of Cheat dumps for Research and Detection.☆16Updated last month
- A x86_64 software emulator☆162Updated 5 months ago
- A driver to implement IOCTL hooking☆27Updated 3 years ago
- A simple and heavily documented series of test hypervisors built for 64-bit Windows 10 systems running under Intel's VT-x☆34Updated 5 years ago
- Proof-of-concept game using VBS enclaves to protect itself from cheating☆49Updated last year