idandev / hidefile-kernel-module
A simple kernel module who hides a file by hooking the getdents64 syscall.
☆10Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for hidefile-kernel-module
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆40Updated last year
- Kernel ReClassEx☆63Updated last year
- ☆70Updated 2 years ago
- vdk is a set of utilities used to help with exploitation of a vulnerable driver.☆39Updated 2 years ago
- Windows PDB parser for kernel-mode environment.☆90Updated last year
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆33Updated last month
- A method to Disable DSE using .data ptr hooks☆26Updated 9 months ago
- A simple ida python script to find .data ptr☆47Updated last year
- Kernel Level NMI Callback Blocker☆32Updated 2 months ago
- Binary rewriter for 64-bit PE files.☆43Updated 9 months ago
- A series of methods used to detect kernel shellcode for tencent game safe race 2024☆33Updated 7 months ago
- POC Hook of nt!HvcallCodeVa☆50Updated last year
- Library to manipulate drivers that expose a physical memory read/write primitive.☆21Updated last year
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆49Updated 2 years ago
- ☆24Updated last month
- A poc that abuses Enclave☆36Updated 2 years ago
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆39Updated 5 months ago
- A Hyper-V Hacking Framework For Windows 10 x64 (AMD & Intel)☆41Updated last year
- A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe☆69Updated last year
- just proof of concept. hooking MmCopyMemory PG safe.☆63Updated last year
- intel vt-x type 2 hypervisor☆48Updated 5 months ago
- x64 Windows implementation of virtual-address to physical-address translation☆41Updated 3 years ago
- clearing traces of a loaded driver☆44Updated 2 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆61Updated last year
- DSE & PG bypass via BYOVD attack☆37Updated 7 months ago
- nmi stackwalking + module verification☆91Updated 10 months ago
- A library to assist with memory & code protection.☆53Updated 8 months ago
- ntoskrnl .data hooks for UM-KM communication☆34Updated 5 months ago
- InfinityHookProMax: Make InfinityHook great great again☆42Updated last year
- Shows an example of how to implement VT-d/AMD-Vi on Windows☆81Updated last year