SanseoLab / simpleAVdriverLinks
Simple AntiVirus Driver example
☆39Updated 8 years ago
Alternatives and similar repositories for simpleAVdriver
Users that are interested in simpleAVdriver are comparing it to the libraries listed below
Sorting:
- A minifilter driver preserves all modified and deleted files.☆80Updated 10 years ago
- Windows Simple Process Logger implemented as driver☆18Updated 8 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Updated 10 years ago
- Protects deletion of files with a specified extension using a kernel-mode driver.☆76Updated 7 years ago
- Windows Monitoring Agent (process creation + DLL loading monitor + network monitor + file system access monitor + etc)☆63Updated 7 years ago
- A command line tool to load and unload a device driver.☆46Updated 8 years ago
- A sample on how to inject a DLL from a kernel driver☆61Updated 9 years ago
- kernel-mode TDI client which can send and receive HTTP requests☆56Updated 7 years ago
- Open Source Libraries Collection☆24Updated 10 years ago
- ☆36Updated 8 years ago
- Library for ETW, ProcessTracker sample based on ETW☆34Updated 8 years ago
- A-Protect Anti Rootkit Tool☆56Updated 12 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆61Updated 5 years ago
- 内核级ARK工具。☆62Updated 9 years ago
- PoC for detecting and dumping process hollowing code injection☆52Updated 7 years ago
- ☆27Updated 6 years ago
- This is a simple driver with x64 inline assembly☆57Updated 5 years ago
- fork HoShiMin Avanguard☆20Updated 7 years ago
- An API Monitor based on Instrumentation☆44Updated 8 years ago
- ☆48Updated 8 years ago
- ☆36Updated 5 years ago
- This is a sample that shows how to leverage SetThreadContext for DLL injection☆85Updated 8 years ago
- Hook IDT vector 0xb2 to detect SCI in 64bit windows.☆34Updated 3 years ago
- Analyze and attack windows applications using dll hijacking vulnerabilities☆59Updated 6 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆53Updated last year
- A simple rootkit to hide a process☆47Updated 12 years ago
- x64 Kernel Hooks Detection☆24Updated 9 years ago
- 小型主动防御引擎☆57Updated 9 years ago
- Wow64 syscall hook☆42Updated 8 years ago
- just an lite AntiRootkit for interesting☆24Updated 10 years ago