Signal-Labs / iat_unhook_sample

(First Public?) Sample of unhooking ntdll (All Exports & IAT imports) hooks in Rust using in-memory disassembly, avoiding direct syscalls and all hooked functions (incl. hooked NtProtectVirtualMemory)
130Updated last year

Alternatives and similar repositories for iat_unhook_sample:

Users that are interested in iat_unhook_sample are comparing it to the libraries listed below