Various novel EPT/NPT hook detection mechanisms.
☆29Mar 20, 2026Updated 6 months ago
Alternatives and similar repositories for Bloodhound
Users that are interested in Bloodhound are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Windows kernel driver that detects hypervisors by probing SIDT/LIDT edge cases, paging/TLB behaviors, privilege transitions, and timing e…☆50Mar 3, 2026Updated 6 months ago
- nmi stackwalking + module verification☆176Dec 28, 2023Updated 2 years ago
- ☆29Aug 27, 2025Updated last year
- Using the peculiar behaviour of the VPGATHER instructions to determine if an address will fault before it is truly accessed. All done in …☆64Dec 30, 2025Updated 8 months ago
- Hooking the Windows usermode exception handler☆23Aug 13, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Kernel Level NMI Callback Blocker☆196Apr 23, 2026Updated 4 months ago
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆93Mar 16, 2026Updated 6 months ago
- Simple single file header for creating zero imports drivers. Can be useful for bypassing forensic memory analysis performed by anticheats…☆26May 20, 2026Updated 3 months ago
- A simple C++ driver base with KD data block☆11Jun 25, 2022Updated 4 years ago
- Hyperspace is a multi-purpose tool for Emulating, Injecting, Dumping and Externals.☆87Jun 10, 2026Updated 3 months ago
- ☆22Aug 28, 2024Updated 2 years ago
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆59Sep 20, 2022Updated 3 years ago
- cr3 shuffle driver☆97Mar 24, 2024Updated 2 years ago
- Yet another IDA Pro/Home plugin for deobfuscating stack strings☆161Mar 6, 2026Updated 6 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Hooking Windows' exception dispatcher to protect process's PML4☆271Jan 24, 2025Updated last year
- Kernel anti-cheat for protecting software.☆156Jul 2, 2026Updated 2 months ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆20Jan 1, 2025Updated last year
- modern c++ wrapper around the microsoft portable executable file format☆40Nov 22, 2025Updated 9 months ago
- C++ Assembler with Built-in Mutation Engine☆31Sep 6, 2025Updated last year
- Undocumented MSVC☆50Nov 10, 2025Updated 10 months ago
- ☆18Dec 3, 2025Updated 9 months ago
- usermode thread hijacking detection via working set page fault monitoring☆41Jul 17, 2026Updated 2 months ago
- Windows x64 DLL/Driver manual map injection on a non-present PML4E using physical memory read/writes, direct page table manipulation and …☆115Sep 28, 2025Updated 11 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Very easy to use pdb parsing library with only one header file,You can use it even if you are a fool.☆13Feb 12, 2026Updated 7 months ago
- Use NtSetInformationThread(ThreadBreakOnTermination) for anti-debugging☆16Sep 21, 2019Updated 6 years ago
- Hijacking Hyper-V at Runtime with DDMA☆153Aug 13, 2025Updated last year
- A Kernel Driver that can be used for a cheat or malware base to circumvent common cache & structure table checks. PsLoadedModuleList howe…☆225Apr 23, 2026Updated 4 months ago
- Disk based DMA for ATA and SCSI☆45Sep 22, 2023Updated 2 years ago
- Rewrite and obfuscate code in compiled binaries☆277Dec 13, 2025Updated 9 months ago
- Demonstrates that NvAPI_D3D11_WksReadScanout (undocumented, interface 0xBCB1C536) can read the GPU scanout buffer directly, bypassing any…☆84Mar 8, 2026Updated 6 months ago
- SysCaller: SDK for WindowsAPI via syscalls. Dynamic Resolution, Obfuscation, Multi-Language Bindings, & more!☆69Nov 17, 2025Updated 10 months ago
- ☆53Aug 29, 2024Updated 2 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- .data ptr swapper for newer win32k versions. (Supports Windows 11)☆38Jan 19, 2026Updated 8 months ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆81Apr 13, 2025Updated last year
- Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compat…☆275Jul 18, 2026Updated 2 months ago
- Header-only compile-time variables obfuscation library for C++20 and later. Compiler Support: MSVC (+WDM), Clang, GCC. Architecture Suppo…☆87Jun 21, 2026Updated 2 months ago
- ☆47Jul 3, 2026Updated 2 months ago
- Just check hypervisor in ring0☆16Jun 7, 2023Updated 3 years ago
- C++ Alt syscall hook in 25h2 can be load by KDU☆27Feb 18, 2026Updated 7 months ago