SweetIceLolly / Prevent_Process_CreationLinks
Record & prevent process creation in kernel mode
☆44Updated 3 years ago
Alternatives and similar repositories for Prevent_Process_Creation
Users that are interested in Prevent_Process_Creation are comparing it to the libraries listed below
Sorting:
- Record & prevent file deletion in kernel mode☆44Updated 4 years ago
- Protected Process Light Library☆18Updated 5 years ago
- All Nt Syscall and W32k Syscall in one asm, include, and call it!☆58Updated 3 years ago
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆24Updated 3 years ago
- ☆26Updated 7 years ago
- Elevate arbitrary MSR writes to kernel execution.☆36Updated last year
- Anti-Analysis technique, trick the debugger by Hiding events from it.☆19Updated 3 years ago
- ☆26Updated 4 years ago
- ☆59Updated 3 years ago
- Bypass UAC by abusing the Security Center CPL and hijacking a shell protocol handler☆29Updated 3 years ago
- Library for using direct system calls☆35Updated 4 months ago
- Rookit and anti rookit on Windows platform☆12Updated last year
- An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit☆24Updated 3 years ago
- Bypasses for Windows kernel callbacks PatchGuard protection☆43Updated 3 years ago
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Updated 2 years ago
- A library with four different methods to execute shellcode in a process☆27Updated 5 years ago
- A kernel mode Windows rootkit in development.☆49Updated 3 years ago
- Wow64 Heaven's Gate Hook☆28Updated 3 years ago
- intel vt-x hypervisor ept☆25Updated 5 years ago
- ☆25Updated 2 years ago
- A poc that abuses Enclave☆38Updated 2 years ago
- Data and structures regarding the research done on WdFilter☆12Updated 5 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- silence file system monitoring components by hooking their minifilters☆57Updated last year
- windows kernel pagehook☆40Updated 2 years ago
- A ready-made template for a project based on libpeconv.☆48Updated 4 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆55Updated 2 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆34Updated 3 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆16Updated 3 years ago
- Simple PE Packer Which Encrypts .text Section☆51Updated 8 years ago