Sentient111 / ClearDriverTraces
clearing traces of a loaded driver
☆46Updated 2 years ago
Alternatives and similar repositories for ClearDriverTraces:
Users that are interested in ClearDriverTraces are comparing it to the libraries listed below
- 将驱动映射到会话空间☆34Updated 2 years ago
- ☆71Updated 2 years ago
- ☆47Updated last year
- UM-KM Communication using registry callbacks☆39Updated 4 years ago
- Windows Kernel Misc☆23Updated last year
- ☆50Updated 2 years ago
- Hiding a system thread against conventional means of detection☆37Updated 4 years ago
- Mapping your code on a 0x1000 size page☆70Updated 2 years ago
- ☆29Updated 4 months ago
- Old way for blocking NMI interrupts☆25Updated 2 years ago
- mouseclassservicecallback detection via hook☆49Updated 2 years ago
- A method to Disable DSE using .data ptr hooks☆29Updated 11 months ago
- POC Hook of nt!HvcallCodeVa☆50Updated last year
- Virtual and physical memory hacking library using gigabyte vulnerable driver☆72Updated last year
- InfinityHookProMax: Make InfinityHook great great again☆43Updated last year
- ☆27Updated last year
- fecurity executor from factory☆33Updated 2 years ago
- ☆31Updated 2 years ago
- A library to assist with memory & code protection.☆53Updated 10 months ago
- Kernel Level NMI Callback Blocker☆61Updated 5 months ago
- Old project (2020) reformed. Modifies gRT->GetVariable sub function from EFI_APPLICATION. Tested on Win10 22H2 (AMD).☆46Updated 11 months ago
- ☆67Updated last year
- Example driver on how to use SKLib☆31Updated 2 months ago
- POC usermode <=> kernel communication via ALPC.☆52Updated 7 months ago
- ☆40Updated 3 years ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆82Updated last year
- Discarded Section Manual Map☆67Updated 4 years ago
- ☆11Updated 2 years ago
- An Undetected BE Kernel Driver I developed, Will probably be detected upon releasing this but can be made undetected very easily. Does no…☆64Updated 4 months ago
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆31Updated 10 months ago