i1tao / winsec-arkLinks
Anti-Rootkit Tool for Windows
☆12Updated 7 months ago
Alternatives and similar repositories for winsec-ark
Users that are interested in winsec-ark are comparing it to the libraries listed below
Sorting:
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Updated 2 years ago
- ☆27Updated 2 years ago
- https://www.huorong.cn/☆15Updated last year
- neat way to detect memory read using nt layer function.☆14Updated 2 years ago
- Load Dll into Kernel space☆38Updated 3 years ago
- A simple python script to check evil Visual Studio projects☆20Updated 2 years ago
- 过TP驱动☆28Updated 5 years ago
- shadow tls☆17Updated 3 years ago
- 以shellcode注入其它驱动执行,躲避驱动签名检测,曾pubg项目中使用,,,当然现在,,,☆25Updated 3 years ago
- Windows driver template, using C++20 & cmake & GithubActions☆23Updated last year
- Inject dll to process in driver☆10Updated last year
- ☆23Updated 2 years ago
- 自写驱动内存注入☆28Updated 4 years ago
- A simple example how to decrypt kernel debugger data block☆30Updated 4 years ago
- Black Signature Driver☆24Updated 2 years ago
- 这篇文章的目的是介绍一款实验性项目基于COM命名管道或者Windows Hyper-V虚拟机Vmbus通道实现的运行在uefi上的windbg调试引擎开发心得☆42Updated last year
- windows rootkit☆61Updated last year
- Static Library For Windows Drivers☆38Updated 2 months ago
- direct systemcalls with a modern c++20 interface.☆44Updated 2 years ago
- IAT-Obfuscation to make static analysis of executable harder.☆44Updated 4 years ago
- manual mapping injector☆28Updated last month
- Compile-time + Lifetime, Usermode + Kernelmode, safe and lightweight string crypter library for C++17+, based on skCrypter☆15Updated 3 months ago
- Call NtCreateUserProcess directly as normal.☆75Updated 3 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆20Updated 10 months ago
- ☆27Updated last year
- Walks through the 4-level paging structures in Windows x64☆13Updated 2 years ago
- Fake Timestamps of Driver Certificates while keeping validity.☆18Updated 4 years ago
- Executes Read/Write process memory with `NtQueryCompositionSurfaceStatistics`☆19Updated last year
- Proof-of-Concept software for detecting AV/EDR hooks in Windows libraries.☆31Updated 3 years ago
- A VMBR (Virtual-Machine Based Rootkit) which runs a guest OS and sends the attacker its data☆28Updated last year