ikermit / 11SyscallsLinks
Windows 11 Syscall table. Ready to use in direct syscall. Actively maintained.
☆23Updated 3 years ago
Alternatives and similar repositories for 11Syscalls
Users that are interested in 11Syscalls are comparing it to the libraries listed below
Sorting:
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆113Updated 2 years ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆115Updated last year
- Recon 2023 slides and code☆79Updated 2 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆120Updated last year
- A Python script to download PDB files associated with a Portable Executable (PE)☆125Updated 8 months ago
- Piece of code to detect and remove hooks in IAT☆64Updated 3 years ago
- ☆71Updated 2 years ago
- ☆42Updated 2 years ago
- ☆83Updated last year
- Exploitable drivers, you know what I mean☆153Updated 2 weeks ago
- Windows x64 kernel mode rootkit process hollowing POC.☆188Updated 2 years ago
- Detours implementation (x64/x86) which used only ntdll import☆89Updated last year
- Easy encrypt/decrypt data with TPM☆25Updated last year
- Collection of source code for Polymorphic, Metamorphic, and Permutation Engines used in Malware☆32Updated 5 years ago
- GetModuleHandle (via PEB) and GetProcAddress (via EAT) like☆32Updated 3 years ago
- Various tools, PoCs and experiments related to my blog at https://www.forrest-orr.net/☆39Updated 4 years ago
- masm32 kernel programming, drivers, tutorials, examples, and tools (credits Four-F)☆126Updated 2 years ago
- Admin to Kernel code execution using the KSecDD driver☆258Updated last year
- A novel technique to communicate between threads using the standard ETHREAD structure☆114Updated 4 years ago
- Small PoC of using a Microsoft signed executable as a lolbin.☆138Updated 2 years ago
- Next gen process injection technique☆54Updated 5 years ago
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆79Updated 3 months ago
- Bypass Malware Time Delays☆104Updated 3 years ago
- Splitting and executing shellcode across multiple pages☆103Updated 2 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆117Updated 2 years ago
- using the gpu to hide your payload☆62Updated 3 years ago
- How to set up 2 VirtualBox VM to debug kernel driver using windbg☆56Updated 3 years ago
- Minifilter Callback Patching Proof-of-Concept☆73Updated 2 years ago
- ☆161Updated 2 years ago
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆239Updated 2 years ago