Just an example of a well-known technique to detect memory tampering via Windows Working Sets.
☆18Jan 15, 2022Updated 4 years ago
Alternatives and similar repositories for QueryWorkingSetExample
Users that are interested in QueryWorkingSetExample are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- External Hooking ( Bypasss process byte patching checks | Injector included )☆22Mar 12, 2023Updated 3 years ago
- Interprocess communication via a covert timing channel☆26Oct 24, 2025Updated 9 months ago
- ☆17Apr 10, 2025Updated last year
- Illustrates the concept of return address spoofing, and how it is used.☆14May 13, 2020Updated 6 years ago
- ☆17Jun 30, 2020Updated 6 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- kernel driver used to monitor the activity of BadlionAnticheat.sys by patching its IAT☆32Jul 9, 2021Updated 5 years ago
- Hijack NotifyRoutine for a kernelmode thread☆38Jun 4, 2022Updated 4 years ago
- Use NtSetInformationThread(ThreadBreakOnTermination) for anti-debugging☆16Sep 21, 2019Updated 6 years ago
- 对Windbg以Exdi模式下调试windows做一些修复☆21Aug 25, 2023Updated 2 years ago
- ☆16Jan 9, 2023Updated 3 years ago
- Public Release☆15Mar 27, 2019Updated 7 years ago
- ☆18Feb 5, 2025Updated last year
- Synchronized Kernel Drawing for 24H2☆23Oct 9, 2025Updated 10 months ago
- Disable threat tracing from the kernel..☆14Apr 8, 2022Updated 4 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- hooks gServerHandlers xxxEventWndProc☆12May 1, 2022Updated 4 years ago
- A simple way to spoof return addresses using an exception handler☆42Aug 3, 2022Updated 4 years ago
- Compile-Time Strings and Numbers Encryption for C++20☆59Feb 9, 2025Updated last year
- PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and pre…☆58May 23, 2022Updated 4 years ago
- G-Presto Anti-Cheat Reverse Engineered.☆26Jun 8, 2022Updated 4 years ago
- A lock-free, high-performance logging system designed for Windows kernel drivers☆26Mar 11, 2025Updated last year
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆90May 17, 2023Updated 3 years ago
- ☆20Aug 25, 2023Updated 2 years ago
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆23Nov 22, 2021Updated 4 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Comprehensive demonstration of kernel-mode to user-mode communication methods for Windows driver development.☆26Oct 12, 2025Updated 9 months ago
- Spoofing the NVIDIA GPU UUID by modifying "nvlddmkm.sys"☆20Sep 11, 2024Updated last year
- Walks through the 4-level paging structures in Windows x64☆14Feb 12, 2023Updated 3 years ago
- A PoC application that detects unauthorized external access to select memory regions.☆36Sep 11, 2024Updated last year
- NtCreateUserProcess with CsrClientCallServer for mainstream Windows x64 version☆45Jul 16, 2024Updated 2 years ago
- GDI Render in kernelmode☆10Mar 7, 2020Updated 6 years ago
- Some drivers I've written while solving exercises from Practical Reverse Engineering☆15Jan 9, 2022Updated 4 years ago
- a simple intel vt code both support x86 & x64. PatchGuard monitor.☆76Oct 28, 2021Updated 4 years ago
- silence file system monitoring components by hooking their minifilters☆63Jan 31, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- 🪝 Various EPT hook detection approaches☆155Feb 22, 2026Updated 5 months ago
- Hook NtDeviceIoControlFile with PatchGuard☆104May 10, 2022Updated 4 years ago
- Basic C++20 Type Polymorphism && Type Translation☆17Aug 1, 2025Updated last year
- Proof of Concept Kernel-User Communication using System Thread.☆14Sep 24, 2023Updated 2 years ago
- Bypassing EasyAntiCheat.sys self-integrity by abusing call hierarchy☆81Oct 6, 2022Updated 3 years ago
- ☆66Aug 31, 2023Updated 2 years ago
- 正确解析 _HEAP_VS_***符号 ,支持在最新win11 24h2 运行,替换windbg自带的!pool命令☆17Nov 30, 2024Updated last year