An Attempt to Bypass Memory Scanners By Misusing the ntdll.dll "RT" Section.
☆100Jan 3, 2016Updated 10 years ago
Alternatives and similar repositories for rtsectiontest
Users that are interested in rtsectiontest are comparing it to the libraries listed below
Sorting:
- ☆36Oct 29, 2020Updated 5 years ago
- ☆12Feb 19, 2017Updated 9 years ago
- RVDbg is a debugger/exception handler for Windows processes and has the capability to circumvent anti-debugging techniques. (Cleaner, doc…☆72Sep 5, 2020Updated 5 years ago
- more at http://www.zer0mem.sk/?p=271☆12Jun 11, 2013Updated 12 years ago
- Intel-Process communitation☆10Feb 27, 2017Updated 9 years ago
- Confirms the capability of Hardware-Accelerated Virtualization Technology.☆10Oct 26, 2025Updated 4 months ago
- ☆14Aug 15, 2018Updated 7 years ago
- Test code only. Not reliable for actual use.☆63Jan 1, 2016Updated 10 years ago
- Test code only. Not suitable for actual use.☆96Apr 19, 2015Updated 10 years ago
- Remote execution tool☆14Jan 14, 2014Updated 12 years ago
- use crystalCPUID to identify vt-x & amd-v☆17Apr 8, 2015Updated 10 years ago
- usermode standalone kernel interface☆111Jul 9, 2018Updated 7 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆27May 21, 2014Updated 11 years ago
- Detecting execution of kernel memory where is not backed by any image file☆261Jul 11, 2018Updated 7 years ago
- modify from memorymodule. support exception☆223Oct 22, 2020Updated 5 years ago
- Windows Minifilter driver that redirects any I/O Request of mp3 files to a target file☆18Jul 7, 2015Updated 10 years ago
- ☆18Oct 12, 2014Updated 11 years ago
- Notes my learning steps about Windows-NT☆23May 18, 2017Updated 8 years ago
- ☆125May 23, 2020Updated 5 years ago
- AllMemPro☆46Jan 15, 2018Updated 8 years ago
- Library for kernel and user mode splicing for Windows (x86 and x64).☆64Oct 29, 2012Updated 13 years ago
- kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x☆443Nov 29, 2021Updated 4 years ago
- wow64 syscall filter☆13Nov 12, 2014Updated 11 years ago
- Kernel mode driver loader, injecting into the windows kernel, Rootkit. Driver injections.☆48Nov 9, 2014Updated 11 years ago
- ☆116Oct 1, 2019Updated 6 years ago
- The project was upgraded from https://coder.pub/ and supported VS2017. The original author wrote the detailed design ideas documentation…☆20Sep 18, 2017Updated 8 years ago
- ☆14Jan 10, 2017Updated 9 years ago
- C++ wrapper for capstone (x86 only)☆15Jul 27, 2017Updated 8 years ago
- windows net program☆13Oct 16, 2014Updated 11 years ago
- midfunction d3d basehook for winxp, win7, win8, win10☆17Jan 21, 2019Updated 7 years ago
- Demo List cm/ps/ob/minifilter callback And Patch/Bypass it☆29Dec 5, 2017Updated 8 years ago
- kernel-mode TDI client which can send and receive HTTP requests☆56Jun 9, 2018Updated 7 years ago
- Windbg extension to find PatchGuard pages☆123Jun 24, 2014Updated 11 years ago
- A system call tracer☆10Sep 22, 2014Updated 11 years ago
- windows driver develop kit with c++ mail:maguojun123@126.com☆48Jul 15, 2019Updated 6 years ago
- ☆15Jul 22, 2024Updated last year
- ☆17Mar 3, 2016Updated 9 years ago
- An aggregate of tools used in the core of vmp_dbg plus other parsing utils to parse vmp bc.☆16Oct 18, 2016Updated 9 years ago
- profiling tool for analysising the games, get all the characteristic by hook d3d☆18Oct 10, 2014Updated 11 years ago