☆37Sep 26, 2024Updated last year
Alternatives and similar repositories for EtwKeyboardDetection
Users that are interested in EtwKeyboardDetection are comparing it to the libraries listed below
Sorting:
- ☆18Feb 5, 2025Updated last year
- ☆47Jul 7, 2024Updated last year
- ☆34Mar 3, 2024Updated 2 years ago
- partially disable patchguard up to win11 21H2☆19Jun 3, 2024Updated last year
- ☆16Aug 28, 2024Updated last year
- read / write memory from a proxy process by injecting shellcode☆20Dec 23, 2025Updated 2 months ago
- ☆82Apr 23, 2024Updated last year
- 巨硬☆17Oct 4, 2023Updated 2 years ago
- Unknowncheats Magically Optimized Tidy Mapper using nvaudio☆153Jun 11, 2024Updated last year
- Browse Page Tables on Windows (Page Table Viewer)☆234Apr 2, 2022Updated 3 years ago
- ☆37May 21, 2022Updated 3 years ago
- detect hypervisor with Nmi Callback☆42Sep 25, 2022Updated 3 years ago
- ☆23Oct 28, 2020Updated 5 years ago
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆61Oct 19, 2024Updated last year
- ☆275Sep 2, 2025Updated 6 months ago
- How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver☆26May 29, 2023Updated 2 years ago
- 将驱动映射到会话空间☆38Aug 27, 2022Updated 3 years ago
- intel vt-x type 2 hypervisor☆64Apr 13, 2025Updated 10 months ago
- it's a driver injector or driver loader header lib(Windows)☆12Aug 5, 2023Updated 2 years ago
- Old way for blocking NMI interrupts☆29Sep 6, 2022Updated 3 years ago
- Translate virtual addresses to physical addresses from usermode.☆104Jun 7, 2024Updated last year
- 对debughelp的二次开发☆11Feb 20, 2023Updated 3 years ago
- 可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。☆109Sep 1, 2022Updated 3 years ago
- Windows PDB parser for kernel-mode environment.☆110Jun 7, 2025Updated 8 months ago
- Example of reading process memory through kernel special APC☆111Apr 21, 2023Updated 2 years ago
- ☆361May 11, 2025Updated 9 months ago
- base for testing☆187Sep 28, 2024Updated last year
- Minimalistic HTTP(S) client for the NT kernel☆62Dec 1, 2025Updated 3 months ago
- Standard Kernel Library for Windows manipulation in C++☆201Jun 18, 2025Updated 8 months ago
- Hooking Windows' exception dispatcher to protect process's PML4☆228Jan 24, 2025Updated last year
- undetected eac mapper☆171May 3, 2022Updated 3 years ago
- Disable NMI Callbacks with Kernelmode Driver☆18Mar 15, 2023Updated 2 years ago
- Looks for a vulnerable entry point to bypass BE Anti Cheat or other in Ring3☆19Feb 25, 2023Updated 3 years ago
- windows kernel pagehook☆42Oct 30, 2022Updated 3 years ago
- nmi stackwalking + module verification☆163Dec 28, 2023Updated 2 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆107May 10, 2022Updated 3 years ago
- ☆13Aug 24, 2022Updated 3 years ago
- POC kernel driver with hidden system thread☆13May 14, 2024Updated last year
- modern c++ wrapper around the microsoft portable executable file format☆38Nov 22, 2025Updated 3 months ago