apriorit / APIHookingLibraries
Samples that shows how to use API Hook libraries: Detours, Deviare, MHook, EasyHook to hide files with the "+/*.txt" file name pattern.
☆12Updated 2 years ago
Alternatives and similar repositories for APIHookingLibraries
Users that are interested in APIHookingLibraries are comparing it to the libraries listed below
Sorting:
- Add a new section in the PE file, and copy old import descriptor to the new section then insert a new dll file into the import directory.☆9Updated 3 years ago
- ☆31Updated 4 years ago
- Samples for the article "Interception and modifying TCP connections from kernel on Windows and Linux systems"☆11Updated last year
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆63Updated 8 months ago
- a windows kernel keylogger that works☆20Updated last year
- Record & prevent file deletion in kernel mode☆43Updated 4 years ago
- Static Library For Windows Drivers☆33Updated 3 months ago
- Reverse Socks5 proxy for windows☆14Updated 2 years ago
- A library with four different methods to execute shellcode in a process☆27Updated 5 years ago
- ☆65Updated 6 years ago
- Load Dll into Kernel space☆38Updated 2 years ago
- qq-hook-msg☆17Updated last year
- Easy to include string and wstring obfuscation☆18Updated 3 years ago
- Compile-Time Calls Obfuscator for C++14+☆43Updated last year
- ☆9Updated 4 years ago
- Windows 10/11 unsigned kernel driver load/debugging☆12Updated 2 years ago
- research revolving the windows filtering platform callout mechanism☆32Updated 11 months ago
- Using NtCreateFile and NtDeviceIoControlFile to realize the function of winsock(利用NtCreateFile和NtDeviceIoControlFile 实现winsock的功能)☆111Updated 2 years ago
- Packet Injection With WFP☆13Updated 2 years ago
- Add an empty section to a PE file☆51Updated 7 years ago
- ☆21Updated last year
- NtCreateUserProcess with CsrClientCallServer for mainstream Windows x64 version☆30Updated 10 months ago
- Protect a file from being deleted using windows kernel file system minifilter driver☆37Updated 4 years ago
- A x64 PE Packer/Protector Developed in C++ and VisualStudio☆51Updated last year
- c++ implementation of windows heavens gate☆68Updated 4 years ago
- silence file system monitoring components by hooking their minifilters☆57Updated last year
- Decoder for VMProtect hwids☆17Updated 2 years ago
- COM Explorer☆14Updated 2 months ago
- This script is used to unload PsSetCreateProcessNotifyRoutineEx, PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine and PsSetCr…☆63Updated last year
- Debug Print viewer (user and kernel)☆66Updated last year