christianshub / process-injection-guard
Signature scanner and API hooks to detect malicious process injection
☆27Updated 2 years ago
Alternatives and similar repositories for process-injection-guard
Users that are interested in process-injection-guard are comparing it to the libraries listed below
Sorting:
- Debug Print viewer (user and kernel)☆66Updated last year
- Function hooks in Windows NT Kernel☆23Updated 4 years ago
- Elevate arbitrary MSR writes to kernel execution.☆35Updated last year
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- Intraceptor intercept Windows NT API calls and redirect them to a kernel driver to bypass process/threads handle protections.☆29Updated 2 years ago
- Process Creation, Image Load and Thread Creation Notification☆12Updated last year
- ☆48Updated 6 years ago
- X86/X64 Hardware Breakpoint Manager☆41Updated 3 years ago
- A Windows API hooking library !☆31Updated 2 years ago
- Small project to generate fake DLLs based on an executable's import table☆23Updated 5 years ago
- Small class to parse debug info from PEs, download their respective PDBs from the Microsoft Public Symbol Server and calculate RVAs of fu…☆44Updated 2 years ago
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Updated 2 years ago
- Bypassing kernel patch protection runtime☆20Updated 2 years ago
- Injector with kernel power☆16Updated 4 years ago
- A library with four different methods to execute shellcode in a process☆24Updated 5 years ago
- A poc that abuses Enclave☆38Updated 2 years ago
- Memory Guard Library☆11Updated 4 years ago
- ☆37Updated this week
- Allows you to find the use of ScyllaHide, if your program will debug and restore hooking functions bytes.☆25Updated 5 years ago
- (DEPRECATED) A simple anti-anti debug library for Windows☆29Updated 4 years ago
- Simple library to handle PE files loading, relocating, get/set data, ..., in addition to process handling☆33Updated 5 years ago
- Windows kernel driver template for cmkr and llvm-msvc.☆34Updated last year
- Code injection by hijacking threads in Windows 32-bit applications☆43Updated 6 years ago
- A class to gather information about a process, its threads and modules.☆24Updated 5 years ago
- Stealthy Injector that leverages a vulnerable driver and other exploits to remain undetected☆36Updated 6 years ago
- Small class to help perform syscalls.☆21Updated 2 weeks ago
- Single header library to simplify the usage of direct syscalls. x64/x86☆11Updated 2 years ago
- ☆27Updated last year
- A simple kernel mode driver that hooks some values at the KUSER_SHARED_DATA structure.☆26Updated 5 years ago
- This is a POC Test project for INTEL CPUs on blocking NMI Entries through the IDT Handler.☆50Updated 6 months ago