christianshub / process-injection-guard
Signature scanner and API hooks to detect malicious process injection
☆25Updated last year
Alternatives and similar repositories for process-injection-guard:
Users that are interested in process-injection-guard are comparing it to the libraries listed below
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- Debug Print viewer (user and kernel)☆65Updated last year
- Small class to parse debug info from PEs, download their respective PDBs from the Microsoft Public Symbol Server and calculate RVAs of fu…☆42Updated last year
- Intraceptor intercept Windows NT API calls and redirect them to a kernel driver to bypass process/threads handle protections.☆28Updated 2 years ago
- A poc that abuses Enclave☆36Updated 2 years ago
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Updated 2 years ago
- This is a POC Test project for INTEL CPUs on blocking NMI Entries through the IDT Handler.☆35Updated 4 months ago
- A project on the Unicorn emulator to emulate the code of Pe files in windows☆21Updated 5 months ago
- Disable threat tracing from the kernel..☆12Updated 2 years ago
- Example of hijacking system calls via function pointer tables☆32Updated 3 years ago
- Function hooks in Windows NT Kernel☆21Updated 4 years ago
- Driver Loader/BE Bypass/Win Malware(lol)☆34Updated 5 years ago
- ☆29Updated 3 years ago
- ☆24Updated 5 years ago
- ☆13Updated 4 years ago
- ☆18Updated 2 years ago
- Windows driver template, using C++20 & cmake & GithubActions☆20Updated 6 months ago
- Elevate arbitrary MSR writes to kernel execution.☆26Updated last year
- A simple kernel mode driver that hooks some values at the KUSER_SHARED_DATA structure.☆26Updated 5 years ago
- x64 assembler library☆31Updated 8 months ago
- Injector with kernel power☆16Updated 4 years ago
- Detects if a Kernel mode debugger is active by reading the value of KUSER_SHARED_DATA.KdDebuggerEnabled. It is a high level and portable …☆23Updated 7 years ago
- ☆17Updated 10 months ago
- Bypassing kernel patch protection runtime☆19Updated 2 years ago
- Example of making debugger using Hardware Breakpoint + VEH☆18Updated 3 years ago
- A class to gather information about a process, its threads and modules.☆24Updated 4 years ago
- KNSoft.NDK provides native C/C++ definitions and import libraries for Windows NT and some specifications.☆11Updated this week
- ☆26Updated last year
- a driver to enumerate registered pnp callbacks for a particular interface class based on reversal of IoRegisterPlugPlayNotification☆11Updated 11 months ago
- ☆48Updated 6 years ago