MalwareTech / AppContainerSandbox
An example sandbox using AppContainer (Windows 8+)
☆129Updated 4 years ago
Related projects: ⓘ
- The history of Windows Internals via symbols.☆175Updated 2 years ago
- Simpleator ("Simple-ator") is an innovative Windows-centric x64 user-mode application emulator that leverages several new features that w…☆333Updated 5 years ago
- Open source implementations of Microsoft compression algorithms☆205Updated 4 years ago
- PICO processes toolbox, playground for PICO processes research☆67Updated 6 years ago
- Library that allows you to run 64bit code on a Wow64 32bit process☆138Updated 7 years ago
- Source code for File Test - Interactive File System Test Tool☆255Updated 3 months ago
- Proof of concept implementation of in-memory PE Loader based on ReflectiveDLLInjection Technique☆148Updated 5 years ago
- Persistent IAT hooking application - based on bearparser☆246Updated 2 years ago
- PE file manipulation library.☆62Updated 4 years ago
- PE file manipulation library☆75Updated 4 years ago
- The ultimate hooking library☆253Updated 3 years ago
- x86 Inline hooking engine (using trampolines)☆91Updated 9 years ago
- A local copy of Alex Ionescu's seemingly abandoned native-nt-toolkit project containing knowledge inherited from the ReactOS project.☆53Updated 4 years ago
- windows syscall table from xp ~ 10 rs4☆348Updated 6 years ago
- ☆219Updated 2 years ago
- Library for kernel and user mode splicing for Windows (x86 and x64).☆62Updated 11 years ago
- ☆181Updated 8 years ago
- Named pipe I/O ETW provider for Windows☆66Updated 4 years ago
- A cross-platform library for verifying Authenticode signatures☆136Updated last month
- Recon 2015 Presentation from Alex Ionescu☆228Updated 8 years ago
- Run executables in an AppContainer☆115Updated 5 years ago
- Loading unsigned code into kernel in Windows 10 (64) with help of VMware Workstation Pro/Player design flaw☆135Updated 7 years ago
- A Windows tool that can be used to stream data from named pipe between two other process to Wireshark☆108Updated 6 years ago
- Simple tool to bundle windows DLLs with PE executable☆104Updated 9 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆129Updated 5 years ago
- An strace-like program for the Windows 'native' API☆195Updated last week
- Deviare In Process Instrumentation Engine☆328Updated 4 years ago
- PatchGuard Research☆290Updated 5 years ago
- (unofficial) Hyper-V® Development Kit☆215Updated 7 months ago
- Collection Of Anti-Debugging Tricks☆96Updated 8 years ago