hostzhen / sysarkLinks
Sysark全称system anti-rootkit,是我学习内核写的工具(2013年的代码,后续不会再更新),里面基本上所有的功能都是用内核实现的。这里只是实现了反rootkit部分功能,作为工具的话,本人觉得还欠完善,但作为学习,或有人需要。目前针对的是XP SP2,对于其它版本的系统或者BSOD的问题,需要的人DIY一下。目前实现的功能: 进程/线程/模块、 驱动模块、 SSDT、 Shadow SSDT、 注册表——解析hive文件、 文件、 启动项、 服务
☆27Updated 8 years ago
Alternatives and similar repositories for sysark
Users that are interested in sysark are comparing it to the libraries listed below
Sorting:
- 管道监视器,类似于spyxx之类的东西,一般用于监视目标进程的系统调用.关键词:detours+piep☆23Updated 11 years ago
- ☆34Updated 7 years ago
- x64 Kernel Hooks Detection☆24Updated 9 years ago
- Demo List cm/ps/ob/minifilter callback And Patch/Bypass it☆29Updated 8 years ago
- ☆40Updated 6 years ago
- You don't need install any wdk for development kernel driver☆24Updated 7 years ago
- copy of tdifw lib☆10Updated 8 years ago
- ☆36Updated 5 years ago
- An ark tool's driver☆40Updated 8 years ago
- network filter driver that control network send speed, based on windows tdi framework.☆31Updated last year
- 锁主页驱动☆42Updated 6 years ago
- 给windows窗口全局添加一些功能。☆21Updated 6 years ago
- ☆27Updated 6 years ago
- ☆15Updated last year
- A collection of Windows Administrator tools☆18Updated 12 years ago
- ☆24Updated 8 years ago
- 一个简单的用于win7 x64的驱动级HIPS☆57Updated 9 years ago
- enable libemu run pe file and add some good modify☆14Updated 7 years ago
- LCXL影子系统☆47Updated last year
- ☆29Updated 5 years ago
- Wow64 syscall hook☆42Updated 8 years ago
- Hook IDT vector 0xb2 to detect SCI in 64bit windows.☆34Updated 3 years ago
- A file system filter, you can do some interesting thing, maybe it's cool.☆55Updated 6 years ago
- ☆12Updated 8 years ago
- 在Windows上建立一个开源的强制访问控制框架及SDK。使Windows平台的应用开发者,可以不用关心操作系统底层技术,只用进行简单的SDK调用或配置就可以保护自己的应用程序。☆34Updated 9 years ago
- ☆36Updated 8 years ago
- 解析静态库(Lib)文件,提取出所有函数信息,组织成自定义格式文件☆38Updated 12 years ago
- PDB Explorer 是一个能够查看微软 pdb 文件(Program DataBase,程序数据库)的工具,它能够将 pdb 文件中的 struct、union 及 enum 类型的定义以 C/C++ 的语法显示出来,特别适合 Windows 底层研究人员及 DDK …☆38Updated 10 years ago
- 常用代码类☆13Updated 11 years ago
- x64HOOK库☆18Updated 6 years ago