amitschendel / venom-rootkit
A simple Windows kernel rootkit.
☆90Updated last year
Alternatives and similar repositories for venom-rootkit:
Users that are interested in venom-rootkit are comparing it to the libraries listed below
- CVE-2022-3699 with arbitrary kernel code execution capability☆68Updated 2 years ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆113Updated last year
- Compact MBR Bootkit for Windows☆45Updated 3 years ago
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆154Updated last year
- DSE & PG bypass via BYOVD attack☆42Updated 10 months ago
- windows rootkit☆58Updated 9 months ago
- 2022 Updated Kernelmode-Code☆31Updated 10 months ago
- A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.☆107Updated 3 years ago
- PoC Anti-Rootkit/Anti-Cheat Driver.☆181Updated 5 months ago
- vulnerability in zam64.sys, zam32.sys allowing ring 0 code execution. CVE-2021-31727 and CVE-2021-31728 public reference.☆91Updated 3 years ago
- PoC: Rebuild A New Path Back to the Heaven's Gate (HITB 2021)☆103Updated 3 years ago
- Code Injection, Inject malicious payload via pagetables pml4.☆228Updated 3 years ago
- Hook all callbacks which are registered with LdrRegisterDllNotification☆84Updated 2 years ago
- Obfuscate calls to imports by patching in stubs☆67Updated 3 years ago
- x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code☆201Updated 3 years ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆52Updated 2 years ago
- Finding Truth in the Shadows☆88Updated 2 years ago
- Allows you to find the use of ScyllaHide, if your program will debug and restore hooking functions bytes.☆24Updated 5 years ago
- Dont Call Me Back - Dynamic kernel callback resolver. Scan kernel callbacks in your system in a matter of seconds!☆227Updated 7 months ago
- Kernel Security driver used to block past, current and future process injection techniques on Windows Operating System.☆151Updated 2 years ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆48Updated last year
- silence file system monitoring components by hooking their minifilters☆54Updated last year
- kernel to user mode APC injector☆44Updated 2 years ago
- A simple tool to assemble shellcode ready to be copy-pasted into code☆67Updated 2 years ago
- ☆49Updated last year
- A kernel-mode rootkit with remote control☆209Updated 4 years ago
- A modern, mod independent open source cheat for Enemy Territory☆65Updated last month
- Kernel shellcode injector☆143Updated 3 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆103Updated 2 years ago