VollRagm / PTView
Browse Page Tables on Windows (Page Table Viewer)
☆197Updated 3 years ago
Alternatives and similar repositories for PTView:
Users that are interested in PTView are comparing it to the libraries listed below
- ☆141Updated 4 years ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆275Updated last year
- C++ library for parsing and manipulating PE files statically and dynamically.☆86Updated last year
- x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code☆202Updated 3 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆127Updated 3 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆179Updated last year
- Load your driver like win32k.sys☆251Updated 2 years ago
- ☆152Updated 5 years ago
- Analyze patches in a process☆251Updated 3 years ago
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆143Updated 3 years ago
- Kernel LdrLoadDll injector☆259Updated 6 years ago
- Elevate a process to be a protected process☆149Updated 5 years ago
- ☆198Updated 2 years ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆140Updated last year
- Intercepting DeviceControl via WPP☆133Updated 5 years ago
- Resolve DOS MZ executable symbols at runtime☆95Updated 3 years ago
- Debugger Anti-Detection Benchmark☆325Updated last year
- A mapper that maps shellcode into loaded large page drivers☆269Updated 2 years ago
- Ghetto user mode emulation of Windows kernel drivers.☆133Updated 5 months ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆118Updated last year
- Bypassing PatchGuard on modern x64 systems☆257Updated 2 years ago
- Vectored Exception Handling Hooking Class☆154Updated 6 years ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆112Updated 3 years ago
- ☆177Updated 3 years ago
- Collection of hypervisor detections☆230Updated 6 months ago
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆197Updated 5 months ago
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆212Updated 4 years ago
- Hooking Windows' exception dispatcher to protect process's PML4☆162Updated 2 months ago
- nmi stackwalking + module verification☆109Updated last year
- PE-Dump-Fixer☆105Updated 5 years ago