SwenenzY / section-obfuscation
PE Header (.rdata,.data,.text) obsfucation
☆38Updated 3 years ago
Alternatives and similar repositories for section-obfuscation:
Users that are interested in section-obfuscation are comparing it to the libraries listed below
- PAGE_GUARD based hooking library☆43Updated 2 years ago
- ☆30Updated 2 years ago
- UM-KM Communication using registry callbacks☆39Updated 4 years ago
- Single header code that sets any section's page to No Access☆11Updated 3 years ago
- ☆49Updated last year
- POC Hook of nt!HvcallCodeVa☆51Updated last year
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆32Updated last year
- ☆46Updated 3 years ago
- ☆53Updated 2 years ago
- Bypass using kernel driver (not finish).☆20Updated last year
- PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and pre…☆52Updated 2 years ago
- page table manipulation to gain physical r/w☆40Updated 11 months ago
- A simple MmCopyMemory hook.☆37Updated 2 years ago
- Execute anything in a legit memory region by attacking a windows driver☆19Updated last year
- A lightweight BattlEye emulator of the launcher☆61Updated 2 years ago
- Mapping your code on a 0x1000 size page☆72Updated 2 years ago
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆34Updated 6 months ago
- Handling C++ & __try exceptions without the need of built-in handlers.☆70Updated 3 years ago
- Discarded Section Manual Map☆67Updated 4 years ago
- Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide☆21Updated last year
- Library to manipulate drivers that expose a physical memory read/write primitive.☆25Updated last year
- clearing traces of a loaded driver☆47Updated 2 years ago
- ☆29Updated 7 months ago
- This is an EfiGuard BootLoader that can boot EfiGuard from Usermode with no USB or Setup as a Single Executable with automatic File Dumpi…☆53Updated 7 months ago
- ☆55Updated 2 years ago
- ntoskrnl .data hooks for UM-KM communication☆40Updated 11 months ago
- Old way for blocking NMI interrupts☆26Updated 2 years ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆85Updated last year
- Expanding Kernel Lazy Importer☆31Updated 2 years ago
- x64 manual mapper using inline syscalls☆9Updated 3 years ago