NtQuerySystemInformation / RelocBonus
An obfuscation tool for Windows which instruments the Windows Loader into acting as an unpacking engine.
☆17Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for RelocBonus
- An example of how to use Microsoft Windows Warbird technology☆25Updated last year
- ☆29Updated 2 years ago
- C/C++ antidebugging library for 32 and 64 bit processors☆12Updated 4 months ago
- SoulExtraction is a windows driver library for extracting cert information in windows drivers☆21Updated last year
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆48Updated last year
- A Windows API hooking library !☆30Updated 2 years ago
- EDR PoC WIP LLC☆10Updated 9 months ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- WinXPSP2.Cermalus on stereoids, supporting all 32 bits Windows version. Windows Kernel Virus stuff for noobs☆16Updated last year
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆32Updated last year
- Anti-Analysis technique, trick the debugger by Hiding events from it.☆18Updated 3 years ago
- Signature finder (from PE-bear)☆29Updated 5 months ago
- Bypassing kernel patch protection runtime☆19Updated last year
- Proof-of-concept game using VBS enclaves to protect itself from cheating☆19Updated last week
- ☆27Updated 2 years ago
- XOrCryptEx lightweight C Utility/Algorithm☆11Updated 2 years ago
- Allows you to find the use of ScyllaHide, if your program will debug and restore hooking functions bytes.☆24Updated 5 years ago
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆33Updated 2 years ago
- A driver to implement IOCTL hooking☆23Updated 2 years ago
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆18Updated last month
- ☆17Updated 3 years ago
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆30Updated 2 months ago
- ☆15Updated last year
- ☆57Updated 2 years ago
- ☆12Updated 2 years ago
- silence file system monitoring components by hooking their minifilters☆51Updated 9 months ago
- UEFI bootkit: Hardware Implant. In-Progress☆11Updated 2 years ago
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Updated last year
- Clone running process with ZwCreateProcess☆58Updated 4 years ago