Comprehensive demonstration of kernel-mode to user-mode communication methods for Windows driver development.
☆26Oct 12, 2025Updated 9 months ago
Alternatives and similar repositories for ETOC
Users that are interested in ETOC are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An advanced singular header-only C++20 obfuscation library with encryption and polymorphism.☆133May 28, 2026Updated last month
- An advanced library for protecting/obfuscating kernel drivers using the C++ 17 standard.☆46May 7, 2026Updated 2 months ago
- ☆22Aug 28, 2024Updated last year
- Use GDI in KernelMode☆27Oct 1, 2022Updated 3 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆18Jan 15, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- EMACLab (Gamersclub) anticheat analysis☆20Mar 12, 2026Updated 4 months ago
- ☆27Oct 16, 2017Updated 8 years ago
- DWM hooking-based screenshot tool☆36Sep 13, 2025Updated 10 months ago
- An Unsigned Driver Mapper for Windows 10 22H2 -> Windows 11 23H2 that uses PdFwKrnl to exploit the Read/Write IOCTL Calls to disable DSE …☆33Aug 2, 2024Updated last year
- Written in a couple hours, don't judge :)☆17Jun 3, 2023Updated 3 years ago
- Windows kernel ROP-only implant exposing R/W primitives☆53Feb 1, 2026Updated 5 months ago
- ☆39Jan 9, 2026Updated 6 months ago
- Windows x64 DLL/Driver manual map injection on a non-present PML4E using physical memory read/writes, direct page table manipulation and …☆108Sep 28, 2025Updated 9 months ago
- ☆17Apr 10, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A stealthy anti-fingerprinting toolkit for Windows☆129Aug 5, 2025Updated 11 months ago
- 无痕hook探测☆51Aug 6, 2025Updated 11 months ago
- Hyperspace is a multi-purpose tool for Emulating, Injecting, Dumping and Externals.☆57Jun 10, 2026Updated last month
- Executes Read/Write process memory with `NtQueryCompositionSurfaceStatistics`☆24Feb 10, 2024Updated 2 years ago
- kernel overlay using no hooks to be added to your cheat driver. supports amd/nvidia/intel☆20Nov 23, 2024Updated last year
- ☆16May 8, 2026Updated 2 months ago
- ☆10Dec 28, 2023Updated 2 years ago
- A simple C++ driver base with KD data block☆11Jun 25, 2022Updated 4 years ago
- Windows Kernel Security: Memory Integrity Verification with Disk Verification of ntoskrnl.exe☆28Mar 23, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 对Windbg以Exdi模式下调试windows做一些修复☆21Aug 25, 2023Updated 2 years ago
- Elevate arbitrary MSR writes to kernel execution.☆52Sep 3, 2023Updated 2 years ago
- Detecting window hijacking via ETW and GDI table scanning☆25Apr 11, 2026Updated 3 months ago
- Kernel anti-cheat for protecting software.☆142Jul 2, 2026Updated 2 weeks ago
- BypaPH - Process Hacker's bypass (read/write any process virtual memory & kernel mem) 带签名驱动,驱动级内存读取☆23Sep 3, 2020Updated 5 years ago
- Windows kernel driver template for cmkr (with testsigning).☆40Jul 8, 2023Updated 3 years ago
- Use NtSetInformationThread(ThreadBreakOnTermination) for anti-debugging☆16Sep 21, 2019Updated 6 years ago
- Explit is an internal multihack for Counter-Strike: Global Offensive.☆14May 10, 2019Updated 7 years ago
- LLVM Pass which inserts an opaque predicate at the end of a function, filled with junk bytes to cause IDA analysis to fail (x86_64)☆15May 11, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆74Aug 31, 2022Updated 3 years ago
- Return to a 32-bit environment in an x64 program and trigger a bound exception to communicate with the driver layer via KeRegisterBoundCa…☆24Nov 29, 2025Updated 7 months ago
- HvLoader.efi is an EFI application for loading an external hypervisor loader☆73Jun 12, 2023Updated 3 years ago
- Windows kernel driver that detects hypervisors by probing SIDT/LIDT edge cases, paging/TLB behaviors, privilege transitions, and timing e…☆48Mar 3, 2026Updated 4 months ago
- Demonstrates that NvAPI_D3D11_WksReadScanout (undocumented, interface 0xBCB1C536) can read the GPU scanout buffer directly, bypassing any…☆64Mar 8, 2026Updated 4 months ago
- Interprocess communication via a covert timing channel☆26Oct 24, 2025Updated 8 months ago
- An advanced DKOM for drivers with "DRIVER_OBJECT"☆23Feb 19, 2023Updated 3 years ago