alal4465 / KernelMon
A ProcMon-esque tool for monitoring Windows Kernel Drivers
☆53Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for KernelMon
- Different aproaches to detecting EPT hooks☆84Updated 2 years ago
- ☆93Updated 7 years ago
- Kernel-Mode extended version of https://github.com/microsoft/Detours☆144Updated 2 years ago
- first commit☆57Updated 4 years ago
- Ghetto user mode emulation of Windows kernel drivers.☆122Updated last month
- Static user/kernel mode library that allows access to all functions and global variables by extracting offsets from the PDB☆73Updated last year
- a monitoring windows driver calls kernel api tools☆95Updated 4 months ago
- ☆121Updated 4 years ago
- Using C++ STL on Windows kernle development☆88Updated 5 years ago
- C++ library for parsing and manipulating PE files statically and dynamically.☆87Updated last year
- x64 syscall caller in C++.☆84Updated 6 years ago
- Resolve DOS MZ executable symbols at runtime☆93Updated 3 years ago
- ☆35Updated 5 years ago
- VM devirtualization PoC based on AsmJit and llvm☆104Updated 3 years ago
- Windows Driver Kit Extesion Header (Undoc)☆132Updated 3 years ago
- ☆125Updated last year
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆67Updated 5 years ago
- Collect different versions of Crucial modules.☆127Updated 4 months ago
- A devirtualization engine for Themida.☆91Updated 8 months ago
- Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.☆67Updated 3 weeks ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆142Updated 2 months ago
- Example Windows Kernel-mode Driver which enumerates running processes.☆54Updated 2 years ago
- Windows PDB parser for kernel-mode environment.☆90Updated last year
- Use ci.dll API for validating Authenticode signature of files☆129Updated 2 years ago
- Kernel ReClassEx☆63Updated last year
- reverse engineering of bedaisy.sys (battleyes kernel driver) - Aki2k/BEDaisy☆59Updated 4 years ago
- Handling C++ & __try exceptions without the need of built-in handlers.☆65Updated 3 years ago
- fix vmprotect import function used unicorn-engine.☆92Updated last year
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆41Updated last year