armasm / EasyAntiPatchGuard
Easy Anti PatchGuard
☆215Updated 3 years ago
Alternatives and similar repositories for EasyAntiPatchGuard:
Users that are interested in EasyAntiPatchGuard are comparing it to the libraries listed below
- ☆162Updated 3 years ago
- Hide codes/data in the kernel address space.☆188Updated 3 years ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆112Updated 3 years ago
- ☆198Updated 2 years ago
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆210Updated 4 years ago
- Kernel LdrLoadDll injector☆258Updated 6 years ago
- An x64 page table iterator written in C++ as a kernel mode windows driver.☆108Updated 3 years ago
- ☆153Updated 5 years ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆152Updated 6 months ago
- a more stable & secure read/write virtual memory for kernel mode drivers☆164Updated 5 years ago
- r/w virtual memory without attach☆167Updated last year
- Simple Intel VT-x hypervisor☆294Updated last year
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.☆284Updated 4 years ago
- x64 Windows kernel driver mapper, inject unsigned driver using anycall☆143Updated last year
- ☆177Updated 3 years ago
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆302Updated 2 years ago
- Some psuedo snippets from BattlEye's BEDaisy.sys loaded on Rainbow Six: Siege.☆123Updated 2 years ago
- ☆157Updated 4 years ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆140Updated last year
- Standard Kernel Library for Windows hacking in C++☆135Updated 4 months ago
- 让Etwhook再次伟大! Make InfinityHook Great Again!☆134Updated 3 years ago
- Proof of concept on how to bypass some limitations of a manual mapped driver☆168Updated 4 years ago
- A mapper that maps shellcode into loaded large page drivers☆262Updated 2 years ago
- ☆123Updated 4 years ago
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆69Updated 5 years ago
- Page fault hook use ept (Intel Virtualization Technology)☆183Updated 8 years ago
- The Kernel-Mode Winsock library, supporting TCP, UDP and Unix sockets (DGRAM and STREAM).☆245Updated 2 months ago
- ☆178Updated last year
- 从MmPfnData中枚举进程和页目录基址☆160Updated last year
- Kernel Lazy Importer☆109Updated 11 months ago