cutecatsandvirtualmachines / DmaProtectLinks
Shows an example of how to implement VT-d/AMD-Vi on Windows
☆138Updated last year
Alternatives and similar repositories for DmaProtect
Users that are interested in DmaProtect are comparing it to the libraries listed below
Sorting:
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆82Updated last year
- Example driver on how to use SKLib☆55Updated 9 months ago
- Standard Kernel Library for Windows manipulation in C++☆182Updated 2 months ago
- Kernel driver for detecting Intel VT-x hypervisors.☆189Updated 2 years ago
- base for testing☆173Updated 11 months ago
- IoCreateDriver Implementation, it can be handful if you're trying to bypass anticheats☆98Updated 3 months ago
- Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver☆173Updated last year
- Old project (2020) reformed. Modifies gRT->GetVariable sub function from EFI_APPLICATION. Tested on Win10 22H2 (AMD).☆53Updated last year
- A very simple C++ library for download pdb, get rva of function, global variable and offset from struct.☆150Updated last year
- Some psuedo snippets from BattlEye's BEDaisy.sys loaded on Rainbow Six: Siege.☆126Updated 3 years ago
- ☆213Updated 2 years ago
- Unknowncheats Magically Optimized Tidy Mapper using nvaudio☆134Updated last year
- DWM Overlay without write .text☆99Updated 11 months ago
- ☆138Updated 2 years ago
- nmi stackwalking + module verification☆131Updated last year
- ☆144Updated last year
- Cheat for my own game SecureGame which uses a bootkit to hyperjack Hyper-V in order to access VBS enclave's memory☆76Updated 8 months ago
- A simple ida python script to find .data ptr☆51Updated 2 years ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆118Updated 3 years ago
- Reverse Engineering a signed kernel driver packed and virtualized with VMProtect 3.6☆105Updated 2 years ago
- Static user/kernel mode library that allows access to all functions and global variables by extracting offsets from the PDB☆103Updated 3 months ago
- ☆177Updated 3 years ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆164Updated 11 months ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆98Updated 2 years ago
- ☆53Updated 2 years ago
- just proof of concept. hooking MmCopyMemory PG safe.☆77Updated last year
- kernel anticheat to test your driver against☆173Updated 2 months ago
- 🪝 Various EPT hook detection approaches☆123Updated last month
- Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode☆164Updated 3 years ago
- r/w virtual memory without attach☆191Updated last year