hfiref0x / al-khaserLinks
(This is a fork used primarily to submit patches into upstream repository) Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
☆19Updated 6 months ago
Alternatives and similar repositories for al-khaser
Users that are interested in al-khaser are comparing it to the libraries listed below
Sorting:
- Capcom wrapper with safety in mind.☆83Updated 7 years ago
- disable most common windowsx64 systems patchguard☆86Updated 6 years ago
- Windows Kernel Template Library☆114Updated 3 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆78Updated 14 years ago
- Hooking SSDT with Avast Internet Security Hypervisor☆115Updated 6 years ago
- Windows Manipulation Library (x64, User/Kernelmode)☆77Updated 7 years ago
- Manual PE image mapper☆65Updated 12 years ago
- Windows Driver Kit Extesion Header (Undoc)☆135Updated 4 years ago
- A hypervisor hiding user-mode memory using EPT☆106Updated 7 years ago
- Collect different versions of Crucial modules.☆143Updated last year
- Retrieve pointers to undocumented kernel functions and offsets to members within undocumented structures to use in your driver by using t…☆64Updated 6 years ago
- hook msr by amd svm☆124Updated 5 years ago
- ☆125Updated 5 years ago
- x64 syscall caller in C++.☆93Updated 7 years ago
- anti anti vm dll, used to hide VMWare characteristics as files, processes, services, registry values☆40Updated 7 years ago
- Prototype of hijacking Windows driver dispatch routines in unmapped discardable sections☆55Updated 6 years ago
- This is the P.O.C source for hooking the system calls on Windows 10 (1903) using it's dynamic trace feature weakness☆53Updated 6 years ago
- Some garbage drivers written for getting started☆66Updated 5 years ago
- Communication via callback☆73Updated 6 years ago
- Шаблон полнофункционального драйвера и о бёртки над ядерным API☆115Updated 9 years ago
- windows kernelmode and usermode IAT hook☆149Updated 4 years ago
- Using C++ STL on Windows kernle development☆91Updated 6 years ago
- ayy debuger☆89Updated last year
- Hiding x32/x64 Modules/DLLs using PEB☆61Updated 10 years ago
- ☆98Updated 8 years ago
- Windows driver including couple different techniques for file removal when regular operation isn't possible.☆70Updated 9 years ago
- Kernel Detective☆150Updated 3 years ago
- Intercepting DeviceControl via WPP☆135Updated 6 years ago
- Hide codes/data in the kernel address space.☆187Updated 4 years ago
- the basic version of the ring0 physical memory read/write tool☆90Updated 6 years ago