Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address
☆23Nov 22, 2021Updated 4 years ago
Alternatives and similar repositories for UserVAtoPhysical
Users that are interested in UserVAtoPhysical are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- bypass CRC☆13May 3, 2018Updated 8 years ago
- clearing traces of a loaded driver☆48Jul 2, 2022Updated 4 years ago
- IO隐藏通信封装☆17May 31, 2021Updated 5 years ago
- hooking KiUserApcDispatcher☆26Apr 3, 2017Updated 9 years ago
- Simple Demo of using Windows Hypervisor Platform☆29Jul 14, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Bypassing kernel patch protection runtime☆22Feb 19, 2023Updated 3 years ago
- Windows driver template, using C++20 & cmake & GithubActions☆25Aug 9, 2024Updated last year
- Code Integrity Violation Spotter☆17Jun 11, 2024Updated 2 years ago
- R3劫持所有异常☆14Jan 4, 2021Updated 5 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆73Aug 11, 2023Updated 2 years ago
- ☆118Aug 7, 2022Updated 3 years ago
- A C++ syscall ID extractor for Windows. Developed, debugged and tested on 20H2.☆21May 25, 2021Updated 5 years ago
- Hijack NotifyRoutine for a kernelmode thread☆38Jun 4, 2022Updated 4 years ago
- Source code on the 1.44MB 3.5 floppy accompanying the Windows NT File System Internals book.☆20Jul 31, 2019Updated 6 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- VEH Redirect & VEH Debugger☆24May 18, 2020Updated 6 years ago
- Demo to show how write ALPC Client & Server using native Ntdll.dll syscalls.☆21Jan 25, 2022Updated 4 years ago
- x64 Windows implementation of virtual-address to physical-address translation☆53Jun 3, 2021Updated 5 years ago
- Basic utilities for executing, reading and writing 64-bit data in a 32-bit WoW64 process☆20Jul 8, 2022Updated 4 years ago
- hooks gServerHandlers xxxEventWndProc☆12May 1, 2022Updated 4 years ago
- detect hypervisor with Nmi Callback☆41Sep 25, 2022Updated 3 years ago
- Intraceptor intercept Windows NT API calls and redirect them to a kernel driver to bypass process/threads handle protections.☆30May 18, 2022Updated 4 years ago
- Small driver that uses alternative syscalls feature☆18May 9, 2024Updated 2 years ago
- ☆33Dec 22, 2020Updated 5 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Manually Mapped Windows Kernel Driver + Usermode API for Arbitrary R/W to UM process via a UM thread trapped in kernel, synchronized with…☆16Dec 23, 2020Updated 5 years ago
- kernel driver used to monitor the activity of BadlionAnticheat.sys by patching its IAT☆32Jul 9, 2021Updated 5 years ago
- Some drivers I've written while solving exercises from Practical Reverse Engineering☆15Jan 9, 2022Updated 4 years ago
- A PoC tool for exploiting leaked process and thread handles☆35Feb 13, 2024Updated 2 years ago
- Nice try reading NTDLL from disk, nerd.☆19Apr 18, 2022Updated 4 years ago
- Proof-of-Concept software for detecting AV/EDR hooks in Windows libraries.☆38May 12, 2022Updated 4 years ago
- An example of Windows NT Native API application and kernel driver☆22Feb 10, 2020Updated 6 years ago
- ☆16Jan 9, 2023Updated 3 years ago
- ☆17Jun 30, 2020Updated 6 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- 关闭恶意驱动的文件和注册表保护☆14Jun 28, 2022Updated 4 years ago
- ☆59Jun 8, 2022Updated 4 years ago
- An ark tool's driver☆41May 11, 2017Updated 9 years ago
- An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit☆23Jul 20, 2021Updated 5 years ago
- mouseclassservicecallback detection via hook☆53Feb 7, 2022Updated 4 years ago
- a simple intel vt code both support x86 & x64. PatchGuard monitor.☆76Oct 28, 2021Updated 4 years ago
- ☆163Jul 31, 2022Updated 3 years ago