i1tao / winsec-arkLinks
Anti-Rootkit Tool for Windows
☆12Updated 4 months ago
Alternatives and similar repositories for winsec-ark
Users that are interested in winsec-ark are comparing it to the libraries listed below
Sorting:
- https://www.huorong.cn/☆14Updated last year
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆45Updated 2 years ago
- combine the power of procmon and dbgview into one single application☆9Updated last year
- ☆27Updated 2 years ago
- bootkit驱动映射,三环进程注入加载指定模块☆14Updated 10 months ago
- Load Dll into Kernel space☆38Updated 2 years ago
- Compile-time + Lifetime, Usermode + Kernelmode, safe and lightweight string crypter library for C++17+, based on skCrypter☆14Updated 3 weeks ago
- shadow tls☆17Updated 2 years ago
- 这篇文章的目的是介绍一款实验性项目基于COM命名管道或者Windows Hyper-V虚拟机Vmbus通道实现的运行在uefi上的windbg调试引擎开发心得☆42Updated last year
- A simple python script to check evil Visual Studio projects☆19Updated last year
- ☆27Updated last year
- Based on minhook☆31Updated last year
- IAT-Obfuscation to make static analysis of executable harder.☆44Updated 3 years ago
- neat way to detect memory read using nt layer function.☆14Updated 2 years ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆65Updated 11 months ago
- Windows driver template, using C++20 & cmake & GithubActions☆22Updated last year
- windows rootkit☆61Updated last year
- Executes Read/Write process memory with `NtQueryCompositionSurfaceStatistics`☆15Updated last year
- ☆23Updated 2 years ago
- abusing signed pdfwkrnl.sys for kernel function calling from usermode.☆18Updated 2 months ago
- manual mapping injector☆27Updated 3 years ago
- A simple example how to decrypt kernel debugger data block☆29Updated 4 years ago
- c++ implementation of windows heavens gate☆72Updated 4 years ago
- Black Signature Driver☆24Updated last year
- A simple program to obfuscate code written in cpp.☆50Updated last year
- Static Library For Windows Drivers☆36Updated 5 months ago
- Experiment to use sections as User/Kernelmode comm vector☆22Updated 2 years ago
- 以shellcode注入其它驱动执行,躲避驱动签名检测,曾pubg项目中使用,,,当然现在,,,☆26Updated 2 years ago
- NtCreateUserProcess with CsrClientCallServer for mainstream Windows x64 version☆31Updated last year
- Emulate Drivers in RING3 with self context mapping or unicorn☆19Updated 7 months ago