ivkin25 / Process-Hollowing
An implementation of the Process Hollowing technique.
☆16Updated 4 years ago
Alternatives and similar repositories for Process-Hollowing:
Users that are interested in Process-Hollowing are comparing it to the libraries listed below
- ☆26Updated 3 years ago
- ☆31Updated 4 years ago
- Bypasses for Windows kernel callbacks PatchGuard protection☆43Updated 3 years ago
- Example of hijacking system calls via function pointer tables☆32Updated 3 years ago
- win32/x64 obfuscate framework☆32Updated 5 years ago
- ☆58Updated 2 years ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆48Updated last year
- Hooking Shadow and normal SSDT with Kaspersky Hypervisor and abusing alignment☆23Updated 4 years ago
- windows kernel pagehook☆38Updated 2 years ago
- Protected Process Light Library☆18Updated 4 years ago
- Bypassing kernel patch protection runtime☆19Updated 2 years ago
- ☆26Updated 7 years ago
- This is the P.O.C source for hooking the system calls on Windows 10 (1903) using it's dynamic trace feature weakness☆51Updated 5 years ago
- ☆24Updated 5 years ago
- Shh0ya Kernel Hook Driver☆21Updated 4 years ago
- A packed & protected Module Loader and more, for 64-bit Windows☆28Updated 3 years ago
- An automatic tool for fixing dumped PE files☆41Updated 4 years ago
- arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system☆54Updated 3 years ago
- Bypass UAC by abusing the Security Center CPL and hijacking a shell protocol handler☆28Updated 3 years ago
- An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit☆24Updated 3 years ago
- Hijack NotifyRoutine for a kernelmode thread☆41Updated 2 years ago
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Updated 2 years ago
- A poc that abuses Enclave☆36Updated 2 years ago
- x64 Windows implementation of virtual-address to physical-address translation☆40Updated 3 years ago
- Two PoC of accessing process virtual memory via NT Kernel☆22Updated 3 years ago
- silence file system monitoring components by hooking their minifilters☆55Updated last year
- ☆27Updated 2 years ago
- using gpuz to load driver☆33Updated 5 years ago
- Polymorphic Stub Creator☆32Updated 7 years ago
- ☆48Updated 6 years ago