buzzer-re / Gancho
A tiny Windows hook library for x86/x64
☆14Updated 2 years ago
Alternatives and similar repositories for Gancho:
Users that are interested in Gancho are comparing it to the libraries listed below
- Using Thread Description To Hide Shellcodes☆14Updated 2 years ago
- ☆7Updated 3 weeks ago
- .lib file for linking against the NT CRT☆18Updated 3 years ago
- A Windows API hooking library !☆31Updated 2 years ago
- Hooking Heavens Gate in a weekend☆13Updated 3 years ago
- Detour hooking IRQ1 ISR through IDT (Interrupt Descriptor Table)☆19Updated 2 years ago
- XOrCryptEx lightweight C Utility/Algorithm☆11Updated 3 years ago
- Collection of IDA helpers☆15Updated 2 years ago
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆19Updated 6 months ago
- Collection of structures, prototype and examples for Microsoft Macro Assembler (MASM) x64.☆16Updated 4 years ago
- An example of how to use Microsoft Windows Warbird technology☆27Updated 2 years ago
- ☆10Updated 4 years ago
- EDR PoC WIP LLC☆11Updated last year
- ☆14Updated 4 years ago
- Code Integrity Violation Spotter☆16Updated 10 months ago
- ☆29Updated 3 years ago
- WinXPSP2.Cermalus on stereoids, supporting all 32 bits Windows version. Windows Kernel Virus stuff for noobs☆18Updated last year
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- ☆35Updated 2 years ago
- An attempt at reversing WindowsDefender☆20Updated 6 months ago
- Corsair LL Access driver abuse☆22Updated 4 years ago
- Header-only C++ library for producing PE files.☆32Updated last year
- Rust program for interfacing with the gigabyte driver to gain access to powerful primitives such as arbitrary kernel memcpy.☆17Updated 2 years ago
- Yet another Windows DLL injector.☆39Updated 3 years ago
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆34Updated 7 months ago
- WinREPL is a "read-eval-print loop" shell on Windows that is useful for testing/learning x86 and x64 assembly.☆14Updated 2 years ago
- SoulExtraction is a windows driver library for extracting cert information in windows drivers☆22Updated 2 years ago
- Learn Winapi in this Repo with examples, to understand its abstraction in reverse engineering for Windows.☆10Updated 2 years ago
- x64dbg python3 plugin☆22Updated this week
- An x64 binary executing code that's not inside of it.☆16Updated 2 years ago