hypervisor / kli
Kernel Lazy Importer
☆111Updated 7 months ago
Related projects ⓘ
Alternatives and complementary repositories for kli
- base for testing☆156Updated last month
- An x64 page table iterator written in C++ as a kernel mode windows driver.☆104Updated 3 years ago
- a minimalistic windows hypervisor for amd processors☆98Updated 2 years ago
- Check your detection vectors☆137Updated this week
- ☆132Updated 10 months ago
- Standard Kernel Library for Windows hacking in C++☆91Updated 3 months ago
- Some psuedo snippets from BattlEye's BEDaisy.sys loaded on Rainbow Six: Siege.☆121Updated 2 years ago
- Old project (2020) reformed. Modifies gRT->GetVariable sub function from EFI_APPLICATION. Tested on Win10 22H2 (AMD).☆45Updated 8 months ago
- nmi stackwalking + module verification☆91Updated 10 months ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆110Updated 2 years ago
- manually map driver for a signed driver memory space☆138Updated 3 years ago
- Using CVE-2021-40449 to manual map kernel mode driver☆99Updated 2 years ago
- Kernel driver that uses Shared memory to communicate with UserMode☆84Updated 5 years ago
- ☆52Updated 4 years ago
- Bypassing EasyAntiCheat.sys self-integrity by abusing call hierarchy☆78Updated 2 years ago
- Disks for DMA☆98Updated 3 years ago
- bypass to the p2c(s) that I have run over the past few months.☆53Updated last year
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆80Updated last year
- Handling C++ & __try exceptions without the need of built-in handlers.☆65Updated 3 years ago
- A simple ida python script to find .data ptr☆47Updated last year
- Discarded Section Manual Map☆66Updated 4 years ago
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆67Updated 5 years ago
- A proof of concept demonstrating communication via mapped shared memory structures between a user-mode process and a kernel-mode payload …☆74Updated 3 years ago
- Intercepting DeviceControl via WPP☆128Updated 5 years ago
- ☆70Updated 2 years ago
- External Il2Cpp Framework☆57Updated 3 years ago