Various novel EPT/NPT hook detection mechanisms.
☆26Mar 20, 2026Updated 4 months ago
Alternatives and similar repositories for Bloodhound
Users that are interested in Bloodhound are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Windows kernel driver that detects hypervisors by probing SIDT/LIDT edge cases, paging/TLB behaviors, privilege transitions, and timing e…☆48Mar 3, 2026Updated 4 months ago
- ☆24Aug 27, 2025Updated 10 months ago
- Using the peculiar behaviour of the VPGATHER instructions to determine if an address will fault before it is truly accessed. All done in …☆62Dec 30, 2025Updated 6 months ago
- Kernel Level NMI Callback Blocker☆188Apr 23, 2026Updated 2 months ago
- Hooking the Windows usermode exception handler☆22Aug 13, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆89Mar 16, 2026Updated 4 months ago
- A simple C++ driver base with KD data block☆11Jun 25, 2022Updated 4 years ago
- Simple single file header for creating zero imports drivers. Can be useful for bypassing forensic memory analysis performed by anticheats…☆24May 20, 2026Updated 2 months ago
- ☆22Aug 28, 2024Updated last year
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆59Sep 20, 2022Updated 3 years ago
- cr3 shuffle driver☆94Mar 24, 2024Updated 2 years ago
- Yet another IDA Pro/Home plugin for deobfuscating stack strings☆153Mar 6, 2026Updated 4 months ago
- Kernel anti-cheat for protecting software.☆142Jul 2, 2026Updated 2 weeks ago
- Hooking Windows' exception dispatcher to protect process's PML4☆259Jan 24, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- modern c++ wrapper around the microsoft portable executable file format☆37Nov 22, 2025Updated 7 months ago
- Undocumented MSVC☆49Nov 10, 2025Updated 8 months ago
- C++ Assembler with Built-in Mutation Engine☆31Sep 6, 2025Updated 10 months ago
- ☆18Dec 3, 2025Updated 7 months ago
- Windows x64 DLL/Driver manual map injection on a non-present PML4E using physical memory read/writes, direct page table manipulation and …☆108Sep 28, 2025Updated 9 months ago
- usermode thread hijacking detection via working set page fault monitoring☆38Updated this week
- Very easy to use pdb parsing library with only one header file,You can use it even if you are a fool.☆12Feb 12, 2026Updated 5 months ago
- Use NtSetInformationThread(ThreadBreakOnTermination) for anti-debugging☆16Sep 21, 2019Updated 6 years ago
- Demonstrates that NvAPI_D3D11_WksReadScanout (undocumented, interface 0xBCB1C536) can read the GPU scanout buffer directly, bypassing any…☆64Mar 8, 2026Updated 4 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Hijacking Hyper-V at Runtime with DDMA☆145Aug 13, 2025Updated 11 months ago
- A Kernel Driver that can be used for a cheat or malware base to circumvent common cache & structure table checks. PsLoadedModuleList howe…☆216Apr 23, 2026Updated 2 months ago
- Disk based DMA for ATA and SCSI☆44Sep 22, 2023Updated 2 years ago
- Rewrite and obfuscate code in compiled binaries☆275Dec 13, 2025Updated 7 months ago
- ☆54Aug 29, 2024Updated last year
- SysCaller: SDK for WindowsAPI via syscalls. Dynamic Resolution, Obfuscation, Multi-Language Bindings, & more!☆68Nov 17, 2025Updated 8 months ago
- .data ptr swapper for newer win32k versions. (Supports Windows 11)☆37Jan 19, 2026Updated 6 months ago
- Hyperspace is a multi-purpose tool for Emulating, Injecting, Dumping and Externals.☆57Jun 10, 2026Updated last month
- Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compat…☆267Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆45Jul 3, 2026Updated 2 weeks ago
- Header-only compile-time variables obfuscation library for C++20 and later. Compiler Support: MSVC (+WDM), Clang, GCC. Architecture Suppo…☆84Jun 21, 2026Updated last month
- Just check hypervisor in ring0☆16Jun 7, 2023Updated 3 years ago
- Usermode exploit to bypass any AC using a 0day shatter attack.☆385Nov 26, 2025Updated 7 months ago
- C++ Alt syscall hook in 25h2 can be load by KDU☆27Feb 18, 2026Updated 5 months ago
- A Windows Kernel Driver Emulator base on Unicorn, Kernel Memory Dump and some of native environment☆186Jan 15, 2026Updated 6 months ago
- ☆15Mar 28, 2015Updated 11 years ago