Sysark全称system anti-rootkit,是我学习内核写的工具(2013年的代码,后续不会再更新),里面基本上所有的功能都是用内核实现的。这里只是实现了反rootkit部分功能,作为工具的话,本人觉得还欠完善,但作为学习,或有人需要。目前针对的是XP SP2,对于其它版本的系统或者BSOD的问题,需要的人DIY一下。目前实现的功能: 进程/线程/模块、 驱动模块、 SSDT、 Shadow SSDT、 注册表——解析hive文件、 文件、 启动项、 服务
☆27Dec 26, 2017Updated 8 years ago
Alternatives and similar repositories for sysark
Users that are interested in sysark are comparing it to the libraries listed below
Sorting:
- Final Transparent encrypted version☆14Jan 10, 2017Updated 9 years ago
- 一个简单的用于win7 x64的驱动级HIPS☆57Mar 7, 2016Updated 9 years ago
- 粗暴地枚举管理内核的WFP对象。 Manage kernel WFPs in a brutal way.☆27Jan 14, 2018Updated 8 years ago
- 绕过卡巴斯基主动防御,加载驱动,unhook所有ssdt hook及shadow ssdt hook☆38Sep 27, 2015Updated 10 years ago
- network filter driver that control network send speed, based on windows tdi framework.☆31Feb 16, 2024Updated 2 years ago
- A C++ cross-platform log library.☆13Jun 4, 2022Updated 3 years ago
- This is a demo project to illustrate the way to verify and restore original SST in case of some malware hooks☆33Mar 2, 2017Updated 8 years ago
- An analytical debugger programmed in C++, using Qt.☆22May 20, 2012Updated 13 years ago
- 给windows窗口全局添加一些功能。☆21May 1, 2019Updated 6 years ago
- AllMemPro☆46Jan 15, 2018Updated 8 years ago
- Hook IDT vector 0xb2 to detect SCI in 64bit windows.☆34Aug 27, 2022Updated 3 years ago
- ☆17Mar 3, 2016Updated 9 years ago
- 内核级ARK工具。☆62Aug 1, 2016Updated 9 years ago
- Kinject - kernel dll injector, currently available in x86 version, will be updated to x64 soon.☆32Apr 10, 2015Updated 10 years ago
- Windows device tree walker☆15Sep 19, 2018Updated 7 years ago
- A minifilter driver for detecting and blocking ransomware virus☆27Mar 4, 2018Updated 7 years ago
- An minifilter-based transparent encryptor on Windows.☆30Feb 27, 2017Updated 9 years ago
- Event Tracing for Windows Custom Events☆21Jan 28, 2015Updated 11 years ago
- ☆18Sep 27, 2016Updated 9 years ago
- The project is a demo solution for one of the anti-rootkit techniques aimed on overcoming splicers☆34Mar 13, 2017Updated 8 years ago
- ☆35Jun 17, 2022Updated 3 years ago
- A kernel level anti-rootkit tool which runs on the windows platform.☆92Apr 18, 2014Updated 11 years ago
- 基于WinDivert实现的一个包过滤与截断程序☆13Jul 22, 2018Updated 7 years ago
- A windows kernel driver to Block symbolic link exploit used for privilege escalation.☆15Jul 30, 2020Updated 5 years ago
- ☆12Oct 19, 2017Updated 8 years ago
- 逆向火绒安全软件驱动——sysdiag☆158Jan 15, 2018Updated 8 years ago
- ☆21Feb 12, 2026Updated 2 weeks ago
- A debugger for windows platform☆20Oct 31, 2018Updated 7 years ago
- Windows过滤驱动-helloworld☆24Aug 27, 2015Updated 10 years ago
- WIP - Play with Intel VM Extensions☆23Jun 12, 2017Updated 8 years ago
- Listens for Firewall rule match events generated by Microsoft Hyper-V Virtual Filter Protocol (VFP) extension.☆31Jan 26, 2021Updated 5 years ago
- Kernel Pool Monitor☆127Mar 6, 2022Updated 3 years ago
- pass game protect☆12Apr 26, 2014Updated 11 years ago
- What makes it page☆17Aug 24, 2022Updated 3 years ago
- A-Protect Anti Rootkit Tool☆56Jan 21, 2014Updated 12 years ago
- library, which help to describe or load and execute PE files.☆55Jun 23, 2013Updated 12 years ago
- Capstone disassembly/disassembler framework: Core (Arm, Arm64, M68K, Mips, PPC, Sparc, SystemZ, X86, X86_64, XCore) + bindings (Python, J…☆15May 18, 2019Updated 6 years ago
- ☆29Jan 15, 2021Updated 5 years ago
- ☆36Oct 29, 2020Updated 5 years ago