☆174Sep 9, 2020Updated 5 years ago
Alternatives and similar repositories for Sysmon_reverse
Users that are interested in Sysmon_reverse are comparing it to the libraries listed below
Sorting:
- Open-source EDR kernel-component for system monitoring and DLL injection☆33Nov 14, 2020Updated 5 years ago
- Windows Kernel Driver with C++ runtime☆181Sep 26, 2020Updated 5 years ago
- An Ark tool project,run on Win7 x86/x64☆118Jul 11, 2017Updated 8 years ago
- ☆14Mar 8, 2019Updated 7 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆216Sep 17, 2019Updated 6 years ago
- Analyze Windows x64 Kernel Memory Layout☆130Nov 19, 2020Updated 5 years ago
- ☆125May 23, 2020Updated 5 years ago
- ☆48Nov 7, 2018Updated 7 years ago
- Kernel Pool Monitor☆127Mar 6, 2022Updated 4 years ago
- Windows CVE主防(HIPS/HIDS)☆57Apr 29, 2021Updated 4 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆146Feb 23, 2019Updated 7 years ago
- Hide codes/data in the kernel address space.☆188May 8, 2021Updated 4 years ago
- Easily hook WIN32 x64 functions☆18Feb 19, 2025Updated last year
- For Example. See Miro's Blog☆30Nov 26, 2022Updated 3 years ago
- A file system filter, you can do some interesting thing, maybe it's cool.☆55Feb 15, 2019Updated 7 years ago
- ☆116Oct 1, 2019Updated 6 years ago
- ☆29Jan 15, 2021Updated 5 years ago
- AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,anal…☆1,113Apr 22, 2021Updated 4 years ago
- Radical Windows ARK☆252Apr 18, 2025Updated 11 months ago
- Windows Ark 工具的工程和一些demo☆193Mar 6, 2016Updated 10 years ago
- Hades HIDS/HIPS for Windows☆309Oct 10, 2025Updated 5 months ago
- ☆39Mar 12, 2019Updated 7 years ago
- 逆向火绒安全软件驱动——sysdiag☆158Jan 15, 2018Updated 8 years ago
- a simple intel vt code both support x86 & x64. PatchGuard monitor.☆77Oct 28, 2021Updated 4 years ago
- Turn off PatchGuard in real time for win7 (7600) ~ later☆1,038Apr 21, 2022Updated 3 years ago
- Unicorn PE is an unicorn based instrumentation project designed to emulate code execution for windows PE files.☆917Dec 29, 2025Updated 2 months ago
- Windows Anti-Rootkit Tool☆546Dec 31, 2025Updated 2 months ago
- 轻量级自动分析病毒程序调用上下文、游戏反调试实现技术平台☆100Jun 21, 2020Updated 5 years ago
- VT-based PCI device monitor (SPI)☆158Oct 29, 2020Updated 5 years ago
- Win7内核私有符号结构转储☆70Sep 3, 2021Updated 4 years ago
- ☆15Jul 22, 2024Updated last year
- Windows Driver Kit Extesion Header (Undoc)☆135Nov 9, 2021Updated 4 years ago
- Hide Driver By MiProcessLoaderEntry☆294May 17, 2019Updated 6 years ago
- Detecting execution of kernel memory where is not backed by any image file☆261Jul 11, 2018Updated 7 years ago
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆748Jun 26, 2017Updated 8 years ago
- Packet Injection With WFP☆16Feb 20, 2023Updated 3 years ago
- ☆26Sep 17, 2017Updated 8 years ago
- kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x☆446Nov 29, 2021Updated 4 years ago
- 之前那份是7600的,每次编译搞得好麻烦。更新一个VS2017可以直接编译的。☆154Jun 5, 2019Updated 6 years ago