armvirus / VanguardTraceLinks
Decrypting and intercepting encrypted imports of Vanguards Kernel Driver
☆31Updated last year
Alternatives and similar repositories for VanguardTrace
Users that are interested in VanguardTrace are comparing it to the libraries listed below
Sorting:
- ☆45Updated last year
- Experiment with PAGE_GUARD protection to hide memory from other processes☆46Updated last year
- cr3 shuffle driver☆49Updated last year
- ☆30Updated 9 months ago
- POC Hook of nt!HvcallCodeVa☆52Updated 2 years ago
- POC Windows kernel driver that spoofs threads for NMI callbacks on x86-64.☆22Updated 3 months ago
- Library to manipulate drivers that expose a physical memory read/write primitive.☆29Updated last year
- Translate virtual addresses to physical addresses from usermode.☆40Updated last year
- ntoskrnl .data hooks for UM-KM communication☆40Updated last year
- partially disable patchguard up to win11 21H2☆19Updated last year
- just proof of concept. hooking MmCopyMemory PG safe.☆75Updated last year
- intel vt-x type 2 hypervisor☆56Updated 3 months ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆45Updated 2 years ago
- Patches DSE by swapping both data ptrs located in SeValidateImageHeader && SeValidateImageData☆20Updated last year
- Windows driver mapper via the UEFI☆47Updated this week
- A simple MmCopyMemory hook.☆38Updated 3 years ago
- The sequel to Voyager☆65Updated 10 months ago
- A method to Disable DSE using .data ptr hooks☆33Updated last year
- ☆78Updated last year
- PoC kernel to usermode injection☆87Updated last year
- ☆46Updated 5 months ago
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆42Updated 8 months ago
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆32Updated last year
- Kernel Level NMI Callback Blocker☆108Updated 10 months ago
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆46Updated last year
- How to use PiDqSerializationWrite. Introduces how to safely read and write from mapped driver☆25Updated 2 years ago
- Old way for blocking NMI interrupts☆27Updated 2 years ago
- Achieving code execution through abusing vectored exception handling☆17Updated 2 years ago
- Load driver on boot before anti-cheats☆32Updated last year
- driver that communicates using a shared section☆65Updated 4 months ago