can1357 / linux-pe
COFF and Portable Executable format described using standard C++ with no dependencies.
☆278Updated last month
Alternatives and similar repositories for linux-pe:
Users that are interested in linux-pe are comparing it to the libraries listed below
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆586Updated 2 months ago
- A modern c++ implementation of windows heavens gate☆217Updated 4 years ago
- The Universal C++ RunTime library, supporting kernel-mode C++ exception-handler and STL.☆400Updated 9 months ago
- System call hook for Windows 10 20H1☆483Updated 3 years ago
- Collection of undocumented Windows API declarations.☆308Updated 2 weeks ago
- C++ STL in the Windows Kernel with C++ Exception Support☆407Updated last year
- C++17 PE manualmapper☆340Updated 3 years ago
- Inline syscalls made easy for windows on clang☆700Updated 9 months ago
- IDA Pro plugin to make bitfield accesses easier to grep☆232Updated 2 months ago
- A x64 Windows Rootkit using SSDT or Hypervisor hook☆532Updated 3 months ago
- This program remaps its image to prevent the page protection of pages contained in the image from being modified via NtProtectVirtualMemo…☆598Updated 6 years ago
- AntiDebugging sample sources written in C++☆337Updated 6 years ago
- Lua in kernel-mode because why not.☆320Updated 3 years ago
- Debugger Anti-Detection Benchmark☆325Updated last year
- Windows inline hooking tool.☆254Updated 6 years ago
- A wrapper library around native windows sytem APIs☆432Updated 4 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆335Updated 2 years ago
- C++ graphics kernel subsystem hook☆506Updated 4 years ago
- Hooking kernel functions by abusing alignment☆238Updated 4 years ago
- A bunch of parsers for PE and PDB formats in C++☆237Updated 11 months ago
- SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.☆380Updated 4 years ago
- Native code virtualizer for x64 binaries☆480Updated 3 months ago
- Simple x86/x86_64 instruction level obfuscator based on a basic SBI engine☆265Updated 2 years ago
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.☆286Updated 4 years ago
- anti debugging library in c++.☆541Updated last year
- UEFI bootkit for driver manual mapping☆533Updated last year
- A VMP to VTIL lifter.☆435Updated 3 years ago
- x86-64 Assembler based on Zydis☆352Updated last month
- Analyze patches in a process☆251Updated 3 years ago
- Header only wrapper around Hex-Rays API in C++20.☆157Updated 3 months ago