☆110May 19, 2019Updated 6 years ago
Alternatives and similar repositories for rootkits
Users that are interested in rootkits are comparing it to the libraries listed below
Sorting:
- ☆68May 19, 2019Updated 6 years ago
- ☆35Mar 20, 2021Updated 5 years ago
- ☆14May 19, 2019Updated 6 years ago
- Data and structures regarding the research done on WdFilter☆12Apr 15, 2020Updated 5 years ago
- Malware monitor template based on MinHook☆17Mar 29, 2015Updated 10 years ago
- The Windows Kernel Programming book samples☆667Sep 25, 2023Updated 2 years ago
- repository with additional materials and source code☆32Jan 18, 2017Updated 9 years ago
- ☆36Oct 27, 2019Updated 6 years ago
- Will try to put here slides from now on when I give a talk☆24Oct 11, 2021Updated 4 years ago
- X32DBG QT5 parsing scripts☆11Sep 8, 2022Updated 3 years ago
- An example code of CiGetCertPublisherName☆16Mar 24, 2022Updated 3 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆62Nov 18, 2020Updated 5 years ago
- ☆29May 10, 2020Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆98Jan 8, 2022Updated 4 years ago
- Bootkits Revisited☆39Jun 3, 2014Updated 11 years ago
- Windows CIFS/SMB packet generation and SMB networking library☆12Aug 25, 2020Updated 5 years ago
- Converts C programs that only use syscalls to 64 bit assembly file.☆12Mar 7, 2021Updated 5 years ago
- Public repository for HEVD exploits☆19Jun 26, 2018Updated 7 years ago
- Headers for linking your software with ntdll.dll☆15Nov 4, 2020Updated 5 years ago
- Conference slides and White-papers☆360Jan 3, 2020Updated 6 years ago
- An automatic tool for fixing dumped PE files☆42Jul 28, 2020Updated 5 years ago
- Hansel - a simple but flexible search for IDA☆26Jul 11, 2019Updated 6 years ago
- This repo contain Android malware samples and analysis☆13Apr 3, 2021Updated 4 years ago
- VT-based PCI device monitor (SPI)☆158Oct 29, 2020Updated 5 years ago
- Set of antianalysis techniques found in malware☆133Aug 25, 2023Updated 2 years ago
- CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit☆25Sep 4, 2018Updated 7 years ago
- MemoryRanger protects kernel data and code by running drivers and hosting data in isolated kernel enclaves using VT-x and EPT features. M…☆232Jul 26, 2020Updated 5 years ago
- A kernel mode Windows rootkit in development.☆49Dec 31, 2021Updated 4 years ago
- Files for my solution to the SSTIC 2021 challenge☆15Jun 14, 2021Updated 4 years ago
- A windows kernel driver to Block symbolic link exploit used for privilege escalation.☆15Jul 30, 2020Updated 5 years ago
- ☆76Sep 30, 2021Updated 4 years ago
- A wrapper for memory hacking related functions (WriteProcessMemory, ReadProcessMemory, etc) as well as a DLL injection function and patte…☆17May 29, 2020Updated 5 years ago
- Simple library to handle PE files loading, relocating, get/set data, ..., in addition to process handling☆32Aug 7, 2019Updated 6 years ago
- HTTP/HTTPS/DNS inspector (windows driver)☆27Feb 20, 2019Updated 7 years ago
- ☆32Apr 24, 2022Updated 3 years ago
- Script and metasploit module for CVE-2018-15982☆11Aug 12, 2020Updated 5 years ago
- IOCTL-Flooder is a verbose tool designed to help with Windows driver fuzzing by brute forcing IOCTLs on loaded drivers. GetLastError is u…☆11Aug 21, 2018Updated 7 years ago
- A way to detect DBI frameworks, Debuggers and VMs.☆24Nov 17, 2020Updated 5 years ago
- ☆10Oct 22, 2017Updated 8 years ago