eddeeh / drv-client
A simple process query/manipulation tool using driver hooked system call. (2019)
☆9Updated 3 years ago
Alternatives and similar repositories for drv-client:
Users that are interested in drv-client are comparing it to the libraries listed below
- P2C Loader based on blackbone, used by isolation.top and others.☆14Updated 7 years ago
- Translates WinDbg "dt" structure dump to a C structure☆13Updated 4 years ago
- A stack and register based virtual machine which can compile and execute arbitrary code in runtime☆43Updated last week
- Interprocess communication library, providing the ability to call functions from each other☆20Updated 5 years ago
- Injector with kernel power☆16Updated 4 years ago
- Remote memory library in C++17.☆31Updated 6 years ago
- simply manual map any system image☆16Updated 4 years ago
- Header only library for binding, reordering and currying of function arguments without cost☆18Updated 6 years ago
- ☆15Updated 4 years ago
- Native file compressor using only the ntdll.dll☆9Updated 6 years ago
- Manually Mapped Windows Kernel Driver + Usermode API for Arbitrary R/W to UM process via a UM thread trapped in kernel, synchronized with…☆15Updated 4 years ago
- x64 assembler library☆31Updated 9 months ago
- reveal and detect of common hooks under win32☆13Updated 4 years ago
- 🧶 The Win32 usermode threading library with UMS/fibers/threads support☆30Updated 5 years ago
- A slightly safer io access library☆13Updated 3 years ago
- An example code of CiGetCertPublisherName☆14Updated 3 years ago
- The updated PE file manipulation library from RetDec project.☆20Updated last year
- Illustrates the concept of return address spoofing, and how it is used.☆13Updated 4 years ago
- a driver to enumerate registered pnp callbacks for a particular interface class based on reversal of IoRegisterPlugPlayNotification☆11Updated last year
- cross platform library to manipulate and extract information of memory regions☆34Updated 6 years ago
- ☆22Updated last year
- eac memory sig maker☆12Updated 3 years ago
- Small class to parse debug info from PEs, download their respective PDBs from the Microsoft Public Symbol Server and calculate RVAs of fu…☆43Updated last year
- Simplifies the Windows Kernel APIs by making the existing function easier to use, and extends them by creating functions that could possi…☆26Updated 7 months ago
- Debug Print viewer (user and kernel)☆65Updated last year
- Abusing RtlAdjustPrivilege and NtSetInformationProcess to cause a BSOD from usermode☆17Updated 2 years ago
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- Memory Dumper For Win10 x64 Processes☆15Updated 4 years ago
- Phantom.Code extension providing Just-In-Time asm x64 compilation based on LLVM☆8Updated 2 years ago
- Experimental imgui app framework for rapid prototyping.☆14Updated last year