colby57 / windows_instrumentation_callbackLinks
PoC demonstrating the usage of undocumented Process Instrumentation Callback for intercepting kernel-to-user transitions (Syscalls, APCs, Exceptions).
☆33Updated 2 months ago
Alternatives and similar repositories for windows_instrumentation_callback
Users that are interested in windows_instrumentation_callback are comparing it to the libraries listed below
Sorting:
- A Windows Direct Syscall Library☆52Updated 9 months ago
- ☆136Updated 3 years ago
- Hooking Windows' exception dispatcher to protect process's PML4☆225Updated last year
- Unknowncheats Magically Optimized Tidy Mapper using nvaudio☆150Updated last year
- manual map unsigned driver over signed memory☆215Updated last year
- IoCreateDriver Implementation, it can be useful if you're trying to bypass anticheats☆122Updated 2 months ago
- ☆83Updated last year
- Kernel Level NMI Callback Blocker☆157Updated 4 months ago
- State of the art DLL injector that took 20 minutes to make☆226Updated 2 years ago
- Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode☆163Updated 3 years ago
- nmi stackwalking + module verification☆157Updated 2 years ago
- base for testing☆185Updated last year
- load unsigned kernel-driver by patching dse in 248 lines☆140Updated last year
- This is my EAC Bypass (Setup) Driver that offers an undetected communication and callback handler/hooking system through IOCTL.☆161Updated 4 months ago
- kernel anticheat to test your driver against☆181Updated 7 months ago
- Standard Kernel Library for Windows manipulation in C++☆198Updated 7 months ago
- Experiment with PAGE_GUARD protection to hide memory from other processes☆54Updated last year
- ☆192Updated 4 years ago
- ☆355Updated 9 months ago
- This is a repo of my previous BEKernelDriver but updated to add better protections and a more detailed setup. also with a good bit of cod…☆133Updated 4 months ago
- A mapper that maps shellcode into loaded large page drivers☆318Updated 3 years ago
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆137Updated 2 years ago
- windows syscalls with a single line and a high level of abstraction. has modern cpp20 wrappers and utilities, range-based DLL and export …☆220Updated 3 months ago
- A Kernel Driver that can be used for a cheat or malware base to circumvent common cache & structure table checks. PsLoadedModuleList howe…☆202Updated 4 months ago
- My EAC & BE Rady CR3 Reading & Writing source that I use for my KM Drivers.☆95Updated 4 months ago
- Kernel driver for detecting Intel VT-x hypervisors.☆192Updated 2 years ago
- ☆159Updated last year
- A simple tool to assemble shellcode ready to be copy-pasted into code☆71Updated 3 years ago
- Kernel driver that .text hooks a syscall in dxgkrnl.sys which can be called from our user-mode client to send instructions like rpm/wpm a…☆204Updated 3 years ago
- x64 Windows kernel driver mapper, inject unsigned driver using anycall☆196Updated last year