christianshub / process-injection-guard
Signature scanner and API hooks to detect malicious process injection
☆22Updated last year
Alternatives and similar repositories for process-injection-guard:
Users that are interested in process-injection-guard are comparing it to the libraries listed below
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Updated last year
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- ☆24Updated 5 years ago
- A poc that abuses Enclave☆36Updated 2 years ago
- Small project to generate fake DLLs based on an executable's import table☆23Updated 4 years ago
- Debug Print viewer (user and kernel)☆65Updated 11 months ago
- Logging library for kernel drivers written for the Windows NT operating system.☆19Updated 7 months ago
- Driver Loader/BE Bypass/Win Malware(lol)☆34Updated 5 years ago
- Intraceptor intercept Windows NT API calls and redirect them to a kernel driver to bypass process/threads handle protections.☆28Updated 2 years ago
- Bypasses for Windows kernel callbacks PatchGuard protection☆42Updated 3 years ago
- A class to gather information about a process, its threads and modules.☆24Updated 4 years ago
- Process Creation, Image Load and Thread Creation Notification☆11Updated last year
- Injector with kernel power☆16Updated 4 years ago
- ☆26Updated last year
- Example of hijacking system calls via function pointer tables☆32Updated 3 years ago
- Simple library to handle PE files loading, relocating, get/set data, ..., in addition to process handling☆31Updated 5 years ago
- (DEPRECATED) A simple anti-anti debug library for Windows☆29Updated 4 years ago
- Based on minhook☆30Updated last year
- Elevate arbitrary MSR writes to kernel execution.☆25Updated last year
- ☆48Updated 6 years ago
- Protected Process Light Library☆18Updated 4 years ago
- Remote memory library in C++17.☆30Updated 6 years ago
- Some crazy PE executables protection kernel driver☆18Updated 4 years ago
- Function hooks in Windows NT Kernel☆21Updated 4 years ago
- Single header library to simplify the usage of direct syscalls. x64/x86☆12Updated last year
- Скрытие строки от отладчиков и декомпиляторов☆49Updated 5 years ago
- A C++ syscall ID extractor for Windows. Developed, debugged and tested on 20H2.☆20Updated 3 years ago
- A simple kernel mode driver that hooks some values at the KUSER_SHARED_DATA structure.☆25Updated 5 years ago
- Windows driver template, using C++20 & cmake & GithubActions☆20Updated 5 months ago