MalwareTech / FstHook
A library for intercepting native functions by hooking KiFastSystemCall
☆72Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for FstHook
- Windbg extension to find PatchGuard pages☆117Updated 10 years ago
- TDL4 style rootkit to spoof read/write requests to master boot record☆129Updated 6 years ago
- Elevation of privilege detector based on HyperPlatform☆117Updated 7 years ago
- Hypervisor based tool for monitoring system register accesses.☆141Updated 6 years ago
- ☆115Updated 12 years ago
- qb-sync is an open source tool to add some helpful glue between IDA Pro and Windbg. Its core feature is to dynamically synchronize IDA's …☆116Updated 9 years ago
- Simple proof of concept code for injecting libraries on 64bit processes from a 32bit process☆93Updated 6 years ago
- ViDi Visual Disassembler (experimental)☆75Updated last year
- Collection Of Anti-Debugging Tricks☆96Updated 8 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub☆76Updated 12 years ago
- KINS Banking Trojan☆62Updated 9 years ago
- IDA Plugin which decodes Windows Device I/O control code into DeviceType, FunctionCode, AccessType and MethodType.☆106Updated 11 months ago
- Loading unsigned code into kernel in Windows 10 (64) with help of VMware Workstation Pro/Player design flaw☆136Updated 7 years ago
- Identifying Virtual Table Functions using VTBL IDA Pro Plugin + Deviare Hooking Engine☆91Updated 11 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆75Updated 9 years ago
- kernel exploitation helper class☆75Updated 7 years ago
- PE file manipulation library.☆63Updated 4 years ago
- x86 Inline hooking engine (using trampolines)☆92Updated 9 years ago
- Library that allows you to run 64bit code on a Wow64 32bit process☆139Updated 7 years ago
- ☆73Updated 6 years ago
- PE file manipulation library☆74Updated 4 years ago
- nyā☆70Updated 9 years ago
- Passive UAC elevation using dll infection☆71Updated 10 years ago
- Hidden kernel mode code execution for bypassing modern anti-rootkits.☆80Updated 13 years ago
- Blackhat 2012 Sample Codes☆91Updated 8 years ago
- Bootkits Revisited☆41Updated 10 years ago
- [ARCHIVED] mov rax, ${Thalium/IceBox}; jmp rax;☆71Updated 5 years ago
- Load a Windows Kernel Driver☆90Updated 7 years ago