RafWu / RansomWatch
Ransomware detection application for Windows using Windows Minifilter driver
☆82Updated 4 years ago
Alternatives and similar repositories for RansomWatch:
Users that are interested in RansomWatch are comparing it to the libraries listed below
- An example of a client and server using Windows' ALPC functions to send and receive data.☆94Updated last month
- ☆31Updated 4 years ago
- A ProcMon-esque tool for monitoring Windows Kernel Drivers☆56Updated 3 years ago
- A minifilter driver preserves all modified and deleted files.☆80Updated 9 years ago
- A driver to intercept low level windows events☆62Updated 5 years ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago
- Use ci.dll API for validating Authenticode signature of files☆137Updated 2 years ago
- Using C++ STL on Windows kernle development☆88Updated 6 years ago
- D☆42Updated 3 years ago
- The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).☆241Updated last month
- Collect various versions of ntoskrnl files☆49Updated last year
- Tutorial & a blog post that demonstrate how to code a Windows driver to inject a custom DLL into all running processes. I coded it from s…☆130Updated 3 years ago
- a monitoring windows driver calls kernel api tools☆102Updated 7 months ago
- ☆12Updated 4 years ago
- This program can retrieve signature information from PE files which signed by one or more certificates on Windows. Supporting multi-signe…☆99Updated 2 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆139Updated 6 years ago
- Protect a file from being deleted using windows kernel file system minifilter driver☆35Updated 3 years ago
- Windows file system minifilter driver which generates backup copies of certain files before they change☆47Updated 6 years ago
- ☆66Updated 6 years ago
- Run Processes as PPL with ELAM☆154Updated 2 years ago
- Simple driver to register all available process, thread, image, Registry, and Object callbacks☆118Updated 7 years ago
- force delete runing .exe application file.or delete any locked file☆70Updated last year
- Documenting system information classes and their uses☆50Updated 3 years ago
- Automated Integration of anti-Reversing methods in PE executables☆50Updated 6 years ago
- Windows disk filter driver to demonstrate sector write redirection☆38Updated 11 years ago
- Example Windows Kernel-mode Driver which enumerates running processes.☆55Updated 2 years ago
- Kernel Security driver used to block past, current and future process injection techniques on Windows Operating System.☆151Updated 2 years ago
- Kernel-Mode extended version of https://github.com/microsoft/Detours☆153Updated 2 years ago
- Collect different versions of Crucial modules.☆130Updated 7 months ago
- Windows Kernel Driver with C++ runtime☆170Updated 4 years ago