dennisbabkin / SigRemover
Utility to remove digital code signature from binary PE files in Windows.
☆14Updated 3 years ago
Alternatives and similar repositories for SigRemover:
Users that are interested in SigRemover are comparing it to the libraries listed below
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 6 years ago
- Subtract one PE file from another!☆20Updated 3 years ago
- Anti-Analysis technique, trick the debugger by Hiding events from it.☆19Updated 3 years ago
- x64 Windows privilege elevation using anycall☆21Updated 3 years ago
- SoulExtraction is a windows driver library for extracting cert information in windows drivers☆21Updated 2 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆32Updated 3 years ago
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆34Updated 3 years ago
- Simple library to handle PE files loading, relocating, get/set data, ..., in addition to process handling☆31Updated 5 years ago
- Injects position-dependent code into a code cave in an executable file, and applies relocations.☆21Updated last year
- A template for projects using both libPeConv and MS Detours☆13Updated last year
- Yet another Windows DLL injector.☆38Updated 3 years ago
- Learn Winapi in this Repo with examples, to understand its abstraction in reverse engineering for Windows.☆9Updated 2 years ago
- ☆18Updated 5 years ago
- INF Studio for easier working with driver installation files☆36Updated last year
- XOrCryptEx lightweight C Utility/Algorithm☆11Updated 2 years ago
- Dump certificates from PE files in different formats☆38Updated last year
- Code Integrity Violation Spotter☆16Updated 8 months ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆34Updated 3 years ago
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆18Updated 4 months ago
- An example of how to use Microsoft Windows Warbird technology☆27Updated last year
- Clone running process with ZwCreateProcess☆57Updated 4 years ago
- Windows kernel PDB data parsed into YAML☆34Updated 3 months ago
- Bypass UAC by abusing shell protocol handlers☆14Updated 3 years ago
- Runs programs as TrustedInstaller☆49Updated 5 years ago
- Listing UDP connections with remote address without sniffing.☆30Updated last year
- ☆18Updated 3 years ago
- Dump mapped PE files from memory to the disk☆19Updated 5 years ago
- allowing um r/w through km from um ioctl ™☆11Updated 3 years ago
- Fake Timestamps of Driver Certificates while keeping validity.☆16Updated 3 years ago
- Plugin for x64dbg to disable parallel loading of dependencies☆19Updated 2 years ago