Luiz-Monad / papersLinks
☆17Updated 5 years ago
Alternatives and similar repositories for papers
Users that are interested in papers are comparing it to the libraries listed below
Sorting:
- Windows PDB parser for kernel-mode environment.☆98Updated 3 months ago
- Another UEFI runtime bootkit☆31Updated 2 years ago
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆59Updated 11 months ago
- Binary rewriter for 64-bit PE files.☆84Updated last year
- A collection of tools, source code, and papers researching Windows' implementation of CET.☆85Updated 4 years ago
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆72Updated 2 years ago
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆164Updated 3 weeks ago
- x64 PE-COFF virtualization driven obfuscation engine☆57Updated 2 years ago
- Visual Studio Project example for using Microsoft's STL in WDM (Windows Kernel-mode Driver)☆25Updated 4 years ago
- Proof-of-concept game using VBS enclaves to protect itself from cheating☆43Updated 10 months ago
- Integration of Microsoft Warbird with the MSVC compiler☆112Updated 2 years ago
- I/O Cache-As-Ram + AMD x86_64 cache line locking | Mirror of https://codeberg.org/3itch/icekit☆17Updated 6 months ago
- A Windows executable (PE) packer (x64) with LZMA compression and with full TLS (Thread Local Storage) support☆78Updated this week
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆79Updated 3 years ago
- x86 and x64 assembly "read-eval-print loop" for Windows☆31Updated 8 years ago
- Kernel ReClassEx☆64Updated last year
- A small tool for rapid enumeration of CPUID, and MSR fields.☆25Updated last year
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆51Updated 4 years ago
- devirtualization vmprotect☆62Updated 2 years ago
- Contains all the applications developed for the Second part of the 7th Edition of Windows Internals book☆114Updated last year
- MalUnpack companion driver☆99Updated last year
- research revolving the windows filtering platform callout mechanism☆33Updated last year
- C++ library for parsing and manipulating PE files statically and dynamically.☆88Updated 2 years ago
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆71Updated 5 years ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆47Updated 2 years ago
- intel vt-x type 2 hypervisor☆56Updated 5 months ago
- ☆21Updated 4 years ago
- A x86_64 software emulator☆149Updated 3 weeks ago
- windows kernel pagehook☆40Updated 2 years ago
- This driver hooks a device object for ioctl and uses mdls to allocate physical pages and manually injects an entry into a process's page …☆15Updated 2 years ago