Executing Kernel Routines via Syscall Table Hijack (Kernel Code Execution)
☆83Jun 7, 2026Updated 2 months ago
Alternatives and similar repositories for win11-kernel-execution-syscall-hijack
Users that are interested in win11-kernel-execution-syscall-hijack are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- kernel callback removal (Bypassing EDR Detections)☆227Jul 2, 2026Updated 2 months ago
- C++ Alt syscall hook in 25h2 can be load by KDU☆28Feb 18, 2026Updated 6 months ago
- Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when a…☆98Jul 7, 2025Updated last year
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Things i do because i saw it on twitter on a weekend☆56Jul 20, 2025Updated last year
- AIDA64DRIVER Elevation of Privilege Vulnerability☆17Oct 25, 2024Updated last year
- Hyperspace is a multi-purpose tool for Emulating, Injecting, Dumping and Externals.☆73Jun 10, 2026Updated 2 months ago
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆116Aug 21, 2025Updated last year
- Bypass user-land hooks by syscall tampering via the Trap Flag☆142Aug 25, 2025Updated last year
- PoC kernel to usermode injection☆136Feb 26, 2024Updated 2 years ago
- A serie of exploits targeting eneio64.sys - Turning Physical Memory R/W into Virtual Memory R/W☆133Oct 19, 2025Updated 10 months ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆472Jun 18, 2026Updated 2 months ago
- Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.☆78Jun 2, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Activation Context Hijacking Evasion Tool☆305Jun 17, 2026Updated 2 months ago
- Intel 64/Windows low-level experiments☆115Aug 26, 2026Updated last week
- Command channel that uses Wi-Fi Beacons as a Bidirectional C2 transport☆45Mar 28, 2026Updated 5 months ago
- demo unhooking functions in ntdll☆28Jul 15, 2025Updated last year
- Finding and classifying ROP gadgets from rp++ output file with some regex and a CLI. Built during an OffSec journey, primarily for the EX…☆36Jun 12, 2026Updated 2 months ago
- Usermode NT Explorer - Query kernel addresses, translate virtual to physical addresses, inspect the PFN database, and more.☆92Mar 16, 2026Updated 5 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 3 months ago
- Commandline spoofing on Windows☆100Jul 19, 2026Updated last month
- Code execution/injection technique using DLL PEB module structure manipulation☆287Jun 4, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Memory hacking library powered by AMD SVM☆27Mar 16, 2023Updated 3 years ago
- Bring your own Unwind Data Framework☆169Mar 15, 2026Updated 5 months ago
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 9 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆86Dec 21, 2022Updated 3 years ago
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆67Apr 2, 2025Updated last year
- ☆55Oct 13, 2025Updated 10 months ago
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆209Apr 21, 2025Updated last year
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 6 months ago
- ☆66Jul 12, 2026Updated last month
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification s…