Rhydon1337 / windows-kernel-file-delete
Force a file delete using a windows kernel driver
☆62Updated 2 years ago
Alternatives and similar repositories for windows-kernel-file-delete:
Users that are interested in windows-kernel-file-delete are comparing it to the libraries listed below
- ☆126Updated 2 years ago
- windows kernel pagehook☆38Updated 2 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆103Updated 2 years ago
- ☆66Updated 6 years ago
- Windows kernel drivers simple HTTP library for modern C++☆42Updated 6 years ago
- Protect a process from code injection, termination and hooking☆42Updated 3 years ago
- ☆71Updated 2 years ago
- Windows PDB parser for kernel-mode environment.☆94Updated 2 years ago
- CVE-2022-3699 with arbitrary kernel code execution capability☆68Updated 2 years ago
- DSE & PG bypass via BYOVD attack☆42Updated 10 months ago
- Hiding a system thread against conventional means of detection☆37Updated 4 years ago
- Only for Stress-Testing☆24Updated 2 years ago
- ☆68Updated 2 years ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆113Updated last year
- windows kernelmode driver to inject dll into each and every process and perform systemwide function hooking☆52Updated 2 years ago
- Collect various versions of ntoskrnl files☆49Updated last year
- A library to assist with memory & code protection.☆53Updated 11 months ago
- POC Hook of nt!HvcallCodeVa☆49Updated last year
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆69Updated 5 years ago
- ☆30Updated 4 years ago
- intel vt-x type 2 hypervisor☆49Updated 7 months ago
- ☆34Updated last year
- silence file system monitoring components by hooking their minifilters☆54Updated last year
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆52Updated 2 years ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆48Updated last year
- ☆26Updated 3 years ago
- detect hypervisor with Nmi Callback☆34Updated 2 years ago
- x64 Windows implementation of virtual-address to physical-address translation☆40Updated 3 years ago
- This project can bypass most of the AC except for some perverts that enable VT to monitor page tables☆40Updated 9 months ago
- ☆10Updated 2 years ago