Signal-Labs / iat_unhook_sample

(First Public?) Sample of unhooking ntdll (All Exports & IAT imports) hooks in Rust using in-memory disassembly, avoiding direct syscalls and all hooked functions (incl. hooked NtProtectVirtualMemory)
128Updated last year

Related projects

Alternatives and complementary repositories for iat_unhook_sample