cristeigabriel / re-sysinternals-suite
Code from process of reversing Sysinternals Suite for educational purposes, with videos to associate them
☆48Updated last year
Related projects ⓘ
Alternatives and complementary repositories for re-sysinternals-suite
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆47Updated 2 months ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆46Updated last year
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆93Updated last year
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- uefi diskless persistence technique + OVMF secureboot bypass☆52Updated 6 months ago
- Hook all callbacks which are registered with LdrRegisterDllNotification☆83Updated last year
- Report and exploit of CVE-2024-21305.☆30Updated 10 months ago
- A journal for $6,000 Riot Vanguard bounty.☆57Updated last year
- Detours implementation (x64/x86) which used only ntdll import☆88Updated 5 months ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆32Updated last year
- devirtualization vmprotect☆61Updated last year
- Windows PDB parser for kernel-mode environment.☆90Updated last year
- Integration of Microsoft Warbird with the MSVC compiler☆85Updated last year
- Finding Truth in the Shadows☆84Updated last year
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆33Updated 2 years ago
- ☆98Updated 2 years ago
- A manual PE mapping implementation, aka reflective loader☆17Updated 2 years ago
- Windows kernel driver template for cmkr and llvm-msvc.☆33Updated 11 months ago
- Me fockin' pe protector☆45Updated 2 years ago
- ☆13Updated last year
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆86Updated 2 years ago
- An x64dbg plugin which marks XFG call signatures as data☆72Updated last year
- Load dll with undocumented functions and debug symbols☆49Updated 4 months ago
- Compileable POC of namazso's x64 return address spoofer.☆47Updated 4 years ago
- ☆65Updated last year
- Fully working kernel-mode VAC bypass☆39Updated 3 weeks ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆48Updated last year
- Disassembler for Zeus VM custom instruction set☆24Updated 9 months ago
- SetWinEventHook Sample☆41Updated last year