VollRagm / KernelBypassSharpLinks
C# Kernel Mode Driver to read and write memory in protected processes
☆366Updated last year
Alternatives and similar repositories for KernelBypassSharp
Users that are interested in KernelBypassSharp are comparing it to the libraries listed below
Sorting:
- C# Kernel Mode Driver example using NativeAOT☆190Updated 3 years ago
- A C# DLL injection library☆214Updated 4 years ago
- C# Anti-Debug and Anti-Dumping techniques using Win32 API functions and tricks.☆289Updated 3 years ago
- A C# port of the MinHook API hooking library☆214Updated 3 years ago
- Dumping processes using the power of kernel space !☆1,019Updated last year
- An automated KoiVM disassembler and devirtualisation utility☆366Updated last year
- DLL that hooks the NtQuerySystemInformation API and hides a process name☆288Updated 2 years ago
- A customizable process dumper.☆142Updated 5 years ago
- Rendering on external windows via hijacking thread contexts☆392Updated 4 years ago
- ConfuserEx unpacking tools☆188Updated 2 years ago
- Kernel mode driver for reading/writing process memory. C/Win32.☆295Updated 7 years ago
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆322Updated 2 years ago
- Manual mapping without creating any threads, with rw only access☆749Updated 5 years ago
- This tool will allow you to spoof the return addresses of your functions as well as system functions.☆483Updated 2 years ago
- Kernel-Mode Driver that loads a dll into every new created process that loads kernel32.dll module☆417Updated 6 years ago
- A deobfuscation tool for Eazfuscator.☆391Updated last year
- A x64 Windows Rootkit using SSDT or Hypervisor hook☆537Updated 5 months ago
- A dnSpy extension to aid reversing of obfuscated assemblies☆360Updated last year
- An Injector that can inject dll into game process protected by anti cheat using SetWindowsHookEx.☆244Updated 5 years ago
- DLL scatter manual mapper☆755Updated 4 years ago
- Using Driver Global Injection dll, it can hide DLL modules☆524Updated 5 years ago
- Loads a signed kernel driver which allows you to map any driver to kernel mode without any traces of the signed / mapped driver.☆339Updated 3 years ago
- A revival of the classic and legendary KsDumper☆473Updated 4 months ago
- VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.☆401Updated 2 years ago
- Generic static analysis framework.☆225Updated 2 months ago
- usermode driver mapper that forcefully loads any signed kernel driver (legit cert) with a big enough section (example: .data, .rdata) to …☆427Updated 3 years ago
- Simple Kernelmode DLL Injector with Manual mapping☆291Updated last year
- Handle elevation DKOM against ObRegisterCallbacks☆301Updated 6 years ago
- Bypassing PatchGuard on modern x64 systems☆260Updated 2 years ago
- Devirtualizer for Eazfuscator.NET☆176Updated 7 years ago