Ricardonacif / gh-anti-debugging-bypass
A simple DLL to bypass the anti debugging methods from GH Anti Debugging with explanation
☆48Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for gh-anti-debugging-bypass
- A mini anti-anti debug hooking library for Windows.☆103Updated 3 years ago
- Various IDA scripts I've created for Reverse engineering.☆78Updated 3 weeks ago
- PE-Dump-Fixer☆102Updated 4 years ago
- A devirtualization engine for Themida.☆91Updated 8 months ago
- A customizable process dumper.☆129Updated 5 years ago
- Class containing Anti-RE, Anti-Debug and Anti-Hook methods. Made for C++/CLI☆101Updated 2 years ago
- ☆121Updated 2 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆117Updated 3 years ago
- manually map driver for a signed driver memory space☆138Updated 3 years ago
- x64 Windows kernel driver mapper, inject unsigned driver using anycall☆114Updated 9 months ago
- game dumper☆40Updated 4 years ago
- Some usefull info when reverse engineering Kernel Mode Anti-Cheat☆67Updated last year
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆136Updated 2 years ago
- Attempts to decrypt JM Xorstr in some x64 binaries☆50Updated last year
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.☆251Updated 4 years ago
- Different aproaches to detecting EPT hooks☆84Updated 2 years ago
- KDM Is a driver that will dumps every drivers that got manually mapped with kdmapper.☆48Updated 2 years ago
- Disables virtualprotect checks/hooks so you can modify memory and change memory protection in binaries protected by VMProtect.☆114Updated 3 years ago
- minimal msvc-windows exclusive lazy importer for C++☆32Updated 3 years ago
- Check your detection vectors☆136Updated last year
- Memory integrity check with CRC32 instruction, section-based☆41Updated last year
- ☆46Updated 3 years ago
- Known ring3 memory protections that can be handled at a simple level.☆62Updated last year
- Obfuscate calls to imports by patching in stubs☆64Updated 3 years ago
- A PoC for requesting HWIDs directly from hardware, skipping any potential hooks or OS support.☆77Updated 3 years ago
- Kernel driver that uses Shared memory to communicate with UserMode☆84Updated 5 years ago
- scans through physical memory and paging tables in kernel mode☆106Updated 4 years ago
- Proof of concept on how to bypass some limitations of a manual mapped driver☆164Updated 4 years ago