buzzer-re / Gancho
A tiny Windows hook library for x86/x64
☆14Updated last year
Alternatives and similar repositories for Gancho:
Users that are interested in Gancho are comparing it to the libraries listed below
- ☆8Updated this week
- Using Thread Description To Hide Shellcodes☆14Updated 2 years ago
- EDR PoC WIP LLC☆10Updated 11 months ago
- Detour hooking IRQ1 ISR through IDT (Interrupt Descriptor Table)☆19Updated last year
- Collection of structures, prototype and examples for Microsoft Macro Assembler (MASM) x64.☆16Updated 4 years ago
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆18Updated 3 months ago
- Collection of IDA helpers☆15Updated 2 years ago
- Input-output driver☆24Updated last year
- WinXPSP2.Cermalus on stereoids, supporting all 32 bits Windows version. Windows Kernel Virus stuff for noobs☆17Updated last year
- ☆10Updated 4 years ago
- An example of how to use Microsoft Windows Warbird technology☆27Updated last year
- Windows kernel driver template for cmkr and llvm-msvc.☆34Updated last year
- Yet another Windows DLL injector.☆38Updated 3 years ago
- automates exploits using ROP chains, using ntdll-scraper☆16Updated 2 years ago
- XOrCryptEx lightweight C Utility/Algorithm☆11Updated 2 years ago
- ollvm 4.0 using clang 10.0.1☆13Updated 3 years ago
- Simple library to handle PE files loading, relocating, get/set data, ..., in addition to process handling☆31Updated 5 years ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- Process injection via KernelCallbackTable☆14Updated 3 years ago
- Collection of scripts and CMake files to easily link to LLVM into your project (Windows, Linux, macOS).☆34Updated 3 months ago
- A Windows API hooking library !☆31Updated 2 years ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Subtract one PE file from another!☆20Updated 3 years ago
- WinREPL is a "read-eval-print loop" shell on Windows that is useful for testing/learning x86 and x64 assembly.☆13Updated 2 years ago
- ☆26Updated 3 months ago
- ☆14Updated 3 years ago
- Static library and headers for linking your software with ntdll.dll☆32Updated 5 years ago
- Anti-Analysis technique, trick the debugger by Hiding events from it.☆19Updated 3 years ago
- Hooking Heavens Gate in a weekend☆13Updated 3 years ago
- Basic utilities for executing, reading and writing 64-bit data in a 32-bit WoW64 process☆16Updated 2 years ago