Xyrem / HyperDeceit
HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system tasks with ease.
☆360Updated last year
Alternatives and similar repositories for HyperDeceit:
Users that are interested in HyperDeceit are comparing it to the libraries listed below
- Debugger Anti-Detection Benchmark☆327Updated last year
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆198Updated 5 months ago
- Signtool for expired certificates☆475Updated last year
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆276Updated 6 months ago
- A small x64 library to load dll's into memory.☆437Updated last year
- PoC Implementation of a fully dynamic call stack spoofer☆760Updated 8 months ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆275Updated last year
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆351Updated 5 months ago
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆154Updated 2 years ago
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆142Updated 2 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆244Updated 2 years ago
- Collection of hypervisor detections☆230Updated 6 months ago
- ☆275Updated this week
- Advanced driver monitoring utility.☆207Updated 2 years ago
- PoC Anti-Rootkit/Anti-Cheat Driver.☆186Updated 6 months ago
- Native code virtualizer for x64 binaries☆480Updated 3 months ago
- A library to develop kernel level Windows payloads for post HVCI era☆394Updated 3 years ago
- Single header version of System Informer's phnt library.☆210Updated last week
- A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and re…☆448Updated last year
- An x86-64 Code Virtualizer☆251Updated 6 months ago
- Using Windows' own bootloader as a shim to bypass Secure Boot☆169Updated 9 months ago
- Bypassing PatchGuard on modern x64 systems☆257Updated 2 years ago
- Process Injection using Thread Name☆256Updated 7 months ago
- Enumerating and removing kernel callbacks using signed vulnerable drivers☆558Updated 2 years ago
- Reverse engineering winapi function loadlibrary.☆188Updated 2 years ago
- A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)☆482Updated last week
- Perfect DLL Proxying using forwards with absolute paths.☆265Updated 6 months ago
- Hooking Windows' exception dispatcher to protect process's PML4☆162Updated 2 months ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆121Updated last year
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆280Updated last year