archercreat / hypereye
My research WIP bluepill hypervisor
☆41Updated last year
Related projects ⓘ
Alternatives and complementary repositories for hypereye
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆48Updated 3 years ago
- How Meltdown and Spectre haunt Anti-Cheat: DVRT details☆20Updated 2 months ago
- This is a ring -1 header framework in order to simplify the creation of hypervisors on SVM☆22Updated last year
- Fix VMProtect 3.xx (tested 3.0.9 to 3.5.0)☆16Updated 2 years ago
- ☆30Updated 2 years ago
- Provides commands to read from and write to arbitrary kernel-mode memory for users with the Administrator privilege. HVCI compatible. No …☆13Updated 4 months ago
- A demonstration of hooking into the VMProtect-2 virtual machine☆17Updated last year
- Type 2 Hypervisor for security research supported by AMD-V hardware assisted virtualization☆39Updated last year
- A basic Secure Virtual Machine hypervisor☆20Updated 3 years ago
- Extensions for x64dbg written in Rust: Telescope and Unicorn powered disassembly☆24Updated last year
- ☆23Updated 8 months ago
- ☆15Updated last year
- Lightweight PDB symbol parser and resolver☆25Updated last week
- A project on the Unicorn emulator to emulate the code of Pe files in windows☆19Updated last month
- ☆20Updated 9 months ago
- POC Hook of nt!HvcallCodeVa☆49Updated last year
- Visual Studio Project example for using Microsoft's STL in WDM (Windows Kernel-mode Driver)☆23Updated 3 years ago
- ☆36Updated last year
- A poc that abuses Enclave☆36Updated 2 years ago
- Binary Ninja plugin for automating VMProtect analysis☆56Updated last year
- Disassembler for Zeus VM custom instruction set☆23Updated 8 months ago
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆32Updated 3 weeks ago
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆69Updated last year
- Disk based DMA for ATA and SCSI☆14Updated last year
- reverse engineering of the windows nt kernel debugger protocol & reimplementation.☆16Updated 4 months ago
- detect hypervisor with Nmi Callback☆34Updated 2 years ago
- A large collection of 32bit and 64bit PE files useful for verifying the correctness of bin2bin transformations☆45Updated 3 months ago
- devirtualization vmprotect☆61Updated last year
- A intel hypervisor, implementing many virtualization techniques☆37Updated last year
- Me fockin' pe protector☆44Updated last year