chkpizza / runtime
VEH Redirect & VEH Debugger
☆23Updated 4 years ago
Alternatives and similar repositories for runtime:
Users that are interested in runtime are comparing it to the libraries listed below
- ☆15Updated last year
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆25Updated 10 years ago
- win32/x64 obfuscate framework☆32Updated 5 years ago
- viewing page boundaries of pages with PAGE_NOACCESS protection reveals the presence of x64dbg.☆23Updated 8 years ago
- Windows Console Monitor☆33Updated 5 years ago
- ☆34Updated 4 years ago
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- This is a ring -1 header framework in order to simplify the creation of hypervisors on SVM☆22Updated last year
- Detects if a Kernel mode debugger is active by reading the value of KUSER_SHARED_DATA.KdDebuggerEnabled. It is a high level and portable …☆23Updated 7 years ago
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆24Updated 3 years ago
- Translates WinDbg "dt" structure dump to a C structure☆13Updated 4 years ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- Dump PDB Symbols including support for Bochs Debugging Format (with wine support)☆15Updated last year
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆48Updated 3 years ago
- Example of hijacking system calls via function pointer tables☆32Updated 3 years ago
- Some eternal WIP stuff :)☆15Updated last week
- x64 assembler library☆31Updated 8 months ago
- ntos shit☆23Updated last year
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆32Updated last year
- a driver to enumerate registered pnp callbacks for a particular interface class based on reversal of IoRegisterPlugPlayNotification☆11Updated 11 months ago
- a demo for x86/x64's paging memory management learning, convert a virtual address from ring3 to physical address in ring0☆17Updated 7 years ago
- ☆21Updated last year
- Code Integrity Violation Spotter☆16Updated 8 months ago
- Windbg extension that allows you analyze Control Flow Guard map☆34Updated 3 years ago
- ☆24Updated 5 years ago
- A driver that supports communication between a Windows guest and HyperWin☆15Updated 4 years ago
- Wow64 syscall hook☆40Updated 7 years ago
- ☆48Updated 6 years ago
- Yet another windows syscall library☆18Updated 4 years ago
- A driver to implement IOCTL hooking☆24Updated 2 years ago