crvvdev / vac-bypass-kernel
Fully working kernel-mode VAC bypass
☆48Updated 2 months ago
Alternatives and similar repositories for vac-bypass-kernel:
Users that are interested in vac-bypass-kernel are comparing it to the libraries listed below
- A simple direct syscall wrapper written in C++ with compatibility for x86 and x64 programs.☆43Updated last year
- silence file system monitoring components by hooking their minifilters☆55Updated 11 months ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆112Updated last year
- WinApi Patcher is a straightforward tool leveraging windows API hooking to patch and modify certain behaviors in a targeted environment.☆41Updated 3 months ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆49Updated last year
- DSE & PG bypass via BYOVD attack☆41Updated 9 months ago
- Compileable POC of namazso's x64 return address spoofer.☆50Updated 4 years ago
- windows rootkit☆55Updated 8 months ago
- spoof return address☆72Updated last year
- Tool to dump EFI runtime drivers.☆35Updated 10 months ago
- kernel to user mode APC injector☆44Updated 2 years ago
- ntoskrnl .data hooks for UM-KM communication☆36Updated 7 months ago
- ☆58Updated 2 years ago
- A C++17 framework designed to enable obfuscation of constants, variables, and strings.☆27Updated last year
- Finding Truth in the Shadows☆85Updated last year
- POC Hook of nt!HvcallCodeVa☆50Updated last year
- Hook all callbacks which are registered with LdrRegisterDllNotification☆84Updated last year
- Experiment with PAGE_GUARD protection to hide memory from other processes☆43Updated 6 months ago
- PoC kernel to usermode injection☆73Updated 10 months ago
- Load dll with undocumented functions and debug symbols☆46Updated 5 months ago
- This is an EfiGuard BootLoader that can boot EfiGuard from Usermode with no USB or Setup as a Single Executable with automatic File Dumpi…☆36Updated 3 months ago
- PoC exploit for HP Hardware Diagnostic's EtdSupp driver☆50Updated last year
- A simple tool to assemble shellcode ready to be copy-pasted into code☆67Updated 2 years ago
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆28Updated 2 months ago
- Me fockin' pe protector☆45Updated 2 years ago
- Makes IDA (most versions) to crash upon opening it.☆78Updated 4 months ago
- Header-only C++ library for producing PE files.☆29Updated last year
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆31Updated 9 months ago