Executing Kernel Routines via Syscall Table Hijack (Kernel Code Execution)
☆84Jun 7, 2026Updated 3 months ago
Alternatives and similar repositories for win11-kernel-execution-syscall-hijack
Users that are interested in win11-kernel-execution-syscall-hijack are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- kernel callback removal (Bypassing EDR Detections)☆228Jul 2, 2026Updated 2 months ago
- C++ Alt syscall hook in 25h2 can be load by KDU☆27Feb 18, 2026Updated 7 months ago
- Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when a…☆97Jul 7, 2025Updated last year
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Things i do because i saw it on twitter on a weekend☆56Jul 20, 2025Updated last year
- AIDA64DRIVER Elevation of Privilege Vulnerability☆17Oct 25, 2024Updated last year
- Hyperspace is a multi-purpose tool for Emulating, Injecting, Dumping and Externals.☆91Jun 10, 2026Updated 3 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆140Aug 25, 2025Updated last year
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆117Aug 21, 2025Updated last year
- PoC kernel to usermode injection☆137Feb 26, 2024Updated 2 years ago
- A serie of exploits targeting eneio64.sys - Turning Physical Memory R/W into Virtual Memory R/W☆132Oct 19, 2025Updated 11 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆473Jun 18, 2026Updated 3 months ago
- Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.☆77Jun 2, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Intel 64/Windows low-level experiments☆118Sep 16, 2026Updated last week
- Activation Context Hijacking Evasion Tool☆308Jun 17, 2026Updated 3 months ago
- Command channel that uses Wi-Fi Beacons as a Bidirectional C2 transport☆46Mar 28, 2026Updated 5 months ago
- demo unhooking functions in ntdll☆27Jul 15, 2025Updated last year
- Finding and classifying ROP gadgets from rp++ output file with some regex and a CLI. Built during an OffSec journey, primarily for the EX…☆37Jun 12, 2026Updated 3 months ago
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆94Mar 16, 2026Updated 6 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆26May 10, 2026Updated 4 months ago
- Commandline spoofing on Windows☆99Jul 19, 2026Updated 2 months ago
- Code execution/injection technique using DLL PEB module structure manipulation☆287Jun 4, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Memory hacking library powered by AMD SVM☆29Mar 16, 2023Updated 3 years ago
- Bring your own Unwind Data Framework☆174Mar 15, 2026Updated 6 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆109Nov 7, 2025Updated 10 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆86Dec 21, 2022Updated 3 years ago
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆68Apr 2, 2025Updated last year
- ☆54Oct 13, 2025Updated 11 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆14Feb 16, 2026Updated 7 months ago
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 3 months ago
- ☆70Jul 12, 2026Updated 2 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- P2P Communications of Named Pipes☆12Jul 30, 2026Updated last month
- Kernel Level NMI Callback Blocker☆198Apr 23, 2026Updated 5 months ago
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆249Aug 21, 2025Updated last year
- ☆40Jun 4, 2026Updated 3 months ago
- Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH☆89Sep 6, 2021Updated 5 years ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆140Aug 31, 2025Updated last year
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆146Apr 6, 2025Updated last year