Executing Kernel Routines via Syscall Table Hijack (Kernel Code Execution)
☆82Jun 7, 2026Updated 2 months ago
Alternatives and similar repositories for win11-kernel-execution-syscall-hijack
Users that are interested in win11-kernel-execution-syscall-hijack are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- kernel callback removal (Bypassing EDR Detections)☆226Jul 2, 2026Updated last month
- C++ Alt syscall hook in 25h2 can be load by KDU☆27Feb 18, 2026Updated 5 months ago
- Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when a…☆98Jul 7, 2025Updated last year
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Things i do because i saw it on twitter on a weekend☆56Jul 20, 2025Updated last year
- AIDA64DRIVER Elevation of Privilege Vulnerability☆17Oct 25, 2024Updated last year
- Hyperspace is a multi-purpose tool for Emulating, Injecting, Dumping and Externals.☆65Jun 10, 2026Updated 2 months ago
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆118Aug 21, 2025Updated 11 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆140Aug 25, 2025Updated 11 months ago
- PoC kernel to usermode injection☆131Feb 26, 2024Updated 2 years ago
- A serie of exploits targeting eneio64.sys - Turning Physical Memory R/W into Virtual Memory R/W☆128Oct 19, 2025Updated 9 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆470Jun 18, 2026Updated 2 months ago
- Command channel that uses Wi-Fi Beacons as a Bidirectional C2 transport☆45Mar 28, 2026Updated 4 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.☆77Jun 2, 2025Updated last year
- Activation Context Hijacking Evasion Tool☆306Jun 17, 2026Updated 2 months ago
- Intel 64/Windows low-level experiments☆108Jul 21, 2026Updated 3 weeks ago
- demo unhooking functions in ntdll☆28Jul 15, 2025Updated last year
- Finding and classifying ROP gadgets from rp++ output file with some regex and a CLI.☆36Jun 12, 2026Updated 2 months ago
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆90Mar 16, 2026Updated 5 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 3 months ago
- Commandline spoofing on Windows☆100Jul 19, 2026Updated 3 weeks ago
- Code execution/injection technique using DLL PEB module structure manipulation☆289Jun 4, 2025Updated last year
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Memory hacking library powered by AMD SVM☆24Mar 16, 2023Updated 3 years ago
- Bring your own Unwind Data Framework☆170Mar 15, 2026Updated 5 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆109Nov 7, 2025Updated 9 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆85Dec 21, 2022Updated 3 years ago
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆67Apr 2, 2025Updated last year
- ☆55Oct 13, 2025Updated 10 months ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆206Apr 21, 2025Updated last year
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 6 months ago
- ☆60Jul 12, 2026Updated last month
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…☆42Jun 4, 2026Updated 2 months ago
- P2P Communications of Named Pipes☆12Jul 30, 2026Updated 2 weeks ago
- Kernel Level NMI Callback Blocker☆192Apr 23, 2026Updated 3 months ago
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆243Aug 21, 2025Updated 11 months ago
- ☆40Jun 4, 2026Updated 2 months ago
- Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH☆90Sep 6, 2021Updated 4 years ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆141Aug 31, 2025Updated 11 months ago