XShar / Win_API_ObfuscationLinks
Скрытие Win API
☆26Updated 5 years ago
Alternatives and similar repositories for Win_API_Obfuscation
Users that are interested in Win_API_Obfuscation are comparing it to the libraries listed below
Sorting:
- Скрытие строки от отладчиков и декомпиляторов☆50Updated 5 years ago
- Stealthy Injector that leverages a vulnerable driver and other exploits to remain undetected☆36Updated 6 years ago
- PAGE_GUARD based hooking library☆46Updated 2 years ago
- Мутация PE x86☆15Updated 6 years ago
- Криптор с антиэмуляцией и полиморфизмом для x64☆15Updated 5 years ago
- using gpuz to load driver☆34Updated 6 years ago
- Detect VM and Hypervisor☆8Updated 4 years ago
- Hijack NotifyRoutine for a kernelmode thread☆42Updated 3 years ago
- MazzCrypt - You won't ever get caught. A [was-private] polymorphic source code parser to randomize executables. Inspired by PolyLoader by…☆12Updated 8 years ago
- x64 manual mapper using inline syscalls☆9Updated 3 years ago
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆50Updated 4 years ago
- A poc that abuses Enclave☆38Updated 2 years ago
- LSASS INJECTOR☆35Updated 6 years ago
- a dumb rpm/wpm example driver☆15Updated 4 years ago
- Hiding a system thread against conventional means of detection☆40Updated 4 years ago
- POC Hook of nt!HvcallCodeVa☆52Updated 2 years ago
- Mapping your code on a 0x1000 size page☆72Updated 3 years ago
- ☆17Updated 4 years ago
- Example of hijacking system calls via function pointer tables☆31Updated 4 years ago
- A library with four different methods to execute shellcode in a process☆27Updated 5 years ago
- Polymorphic Stub Creator☆34Updated 8 years ago
- Register a callback from a Manually mapped kernel module☆16Updated 3 years ago
- UM-KM Communication using registry callbacks☆39Updated 5 years ago
- Allows you to find the use of ScyllaHide, if your program will debug and restore hooking functions bytes.☆26Updated 5 years ago
- Compileable POC of namazso's x64 return address spoofer.☆52Updated 5 years ago
- Using c++23 compile-time magic to produce obfuscated PIC strings and arrays.☆22Updated last year
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆47Updated 2 years ago
- Kernel<->Usermode shared memory communcation using manually mapped driver☆22Updated 3 years ago
- Infects PE files with a shellcode☆19Updated 6 years ago
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆32Updated last year