Executing Kernel Routines via Syscall Table Hijack (Kernel Code Execution)
☆82Jun 7, 2026Updated last month
Alternatives and similar repositories for win11-kernel-execution-syscall-hijack
Users that are interested in win11-kernel-execution-syscall-hijack are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- kernel callback removal (Bypassing EDR Detections)☆224Jul 2, 2026Updated 3 weeks ago
- C++ Alt syscall hook in 25h2 can be load by KDU☆27Feb 18, 2026Updated 5 months ago
- Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when a…☆97Jul 7, 2025Updated last year
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Things i do because i saw it on twitter on a weekend☆56Jul 20, 2025Updated last year
- AIDA64DRIVER Elevation of Privilege Vulnerability☆17Oct 25, 2024Updated last year
- Hyperspace is a multi-purpose tool for Emulating, Injecting, Dumping and Externals.☆59Jun 10, 2026Updated last month
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆115Aug 21, 2025Updated 11 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆140Aug 25, 2025Updated 11 months ago
- PoC kernel to usermode injection☆127Feb 26, 2024Updated 2 years ago
- A serie of exploits targeting eneio64.sys - Turning Physical Memory R/W into Virtual Memory R/W☆124Oct 19, 2025Updated 9 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆469Jun 18, 2026Updated last month
- Command channel that uses Wi-Fi Beacons as a Bidirectional C2 transport☆45Mar 28, 2026Updated 4 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.☆75Jun 2, 2025Updated last year
- Activation Context Hijacking Evasion Tool☆301Jun 17, 2026Updated last month
- Intel 64/Windows low-level experiments☆106Jul 21, 2026Updated last week
- demo unhooking functions in ntdll☆28Jul 15, 2025Updated last year
- Finding and classifying ROP gadgets from rp++ output file with some regex and a CLI.☆33Jun 12, 2026Updated last month
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆89Mar 16, 2026Updated 4 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 2 months ago
- Commandline spoofing on Windows☆100Jul 19, 2026Updated last week
- Code execution/injection technique using DLL PEB module structure manipulation☆288Jun 4, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Memory hacking library powered by AMD SVM☆24Mar 16, 2023Updated 3 years ago
- Bring your own Unwind Data Framework☆160Mar 15, 2026Updated 4 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 8 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆85Dec 21, 2022Updated 3 years ago
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆66Apr 2, 2025Updated last year
- ☆55Oct 13, 2025Updated 9 months ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆206Apr 21, 2025Updated last year
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- ☆55Jul 12, 2026Updated 2 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆40Jun 4, 2026Updated last month
- P2P Communications of Named Pipes☆12Dec 11, 2025Updated 7 months ago
- Kernel Level NMI Callback Blocker☆190Apr 23, 2026Updated 3 months ago
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆232Aug 21, 2025Updated 11 months ago
- ☆40Jun 4, 2026Updated last month
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆140Aug 31, 2025Updated 10 months ago
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆145Apr 6, 2025Updated last year