Kernel Lazy Importer
☆139Apr 13, 2024Updated last year
Alternatives and similar repositories for kli
Users that are interested in kli are comparing it to the libraries listed below
Sorting:
- Kernel driver for detecting Intel VT-x hypervisors.☆202Jul 11, 2023Updated 2 years ago
- ☆192Dec 8, 2021Updated 4 years ago
- Easy Anti PatchGuard☆223Apr 9, 2021Updated 4 years ago
- Analyze patches in a process☆260Jul 28, 2021Updated 4 years ago
- base for testing☆187Sep 28, 2024Updated last year
- a minimalistic windows hypervisor for amd processors☆145Jun 30, 2022Updated 3 years ago
- A demonstration of hooking into the VMProtect-2 virtual machine☆24Nov 9, 2023Updated 2 years ago
- ☆73Aug 31, 2022Updated 3 years ago
- DLL scatter manual mapper☆813Apr 10, 2021Updated 4 years ago
- A mapper that maps shellcode into loaded large page drivers☆329Apr 26, 2022Updated 3 years ago
- IDA scripts for hypervisor (Hyper-v) analysis and reverse engineering automation☆27Dec 7, 2021Updated 4 years ago
- Detect removed thread from PspCidTable.☆75Mar 18, 2022Updated 4 years ago
- 09/2021 reversal of EasyAntiCheat driver☆237Dec 21, 2021Updated 4 years ago
- Standard Kernel Library for Windows manipulation in C++☆203Jun 18, 2025Updated 9 months ago
- Expanding Kernel Lazy Importer☆33Feb 16, 2023Updated 3 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆366Aug 18, 2022Updated 3 years ago
- This tool will allow you to spoof the return addresses of your functions as well as system functions.☆554Nov 12, 2022Updated 3 years ago
- ☆426Jan 1, 2025Updated last year
- A simple ida python script to find .data ptr☆59May 6, 2023Updated 2 years ago
- Inline syscalls made easy for windows on clang☆736Jun 21, 2024Updated last year
- A dumper for all the imports stored within a Windows PE (portable executable).☆15Mar 16, 2022Updated 4 years ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆104Jun 26, 2023Updated 2 years ago
- 🪝 Various EPT hook detection approaches☆143Feb 22, 2026Updated 3 weeks ago
- mouseclassservicecallback detection via hook☆52Feb 7, 2022Updated 4 years ago
- ☆34Apr 11, 2023Updated 2 years ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆121Feb 8, 2022Updated 4 years ago
- ☆225Mar 11, 2023Updated 3 years ago
- ☆69Dec 17, 2020Updated 5 years ago
- Old way for blocking NMI interrupts☆29Sep 6, 2022Updated 3 years ago
- Mapping your code on a 0x1000 size page☆71May 20, 2022Updated 3 years ago
- Drawing from kernelmode without any hooks☆174Jul 7, 2022Updated 3 years ago
- Type 2 Hypervisor for security research supported by AMD-V hardware assisted virtualization☆41Jan 9, 2023Updated 3 years ago
- Disks for DMA☆145Apr 28, 2021Updated 4 years ago
- Collection of hypervisor detections☆300Sep 25, 2024Updated last year
- A simple example how to decrypt kernel debugger data block☆32Feb 8, 2021Updated 5 years ago
- ☆41Mar 23, 2023Updated 2 years ago
- library for importing functions from dlls in a hidden, reverse engineer unfriendly way☆1,903Aug 3, 2023Updated 2 years ago
- BattlEye shellcodes tester☆151Jan 3, 2022Updated 4 years ago
- A wrapper class to hide the original calling address of a function☆54Aug 9, 2020Updated 5 years ago