j321521621 / pipemonitor
管道监视器,类似于spyxx之类的东西,一般用于监视目标进程的系统调用.关键词:detours+piep
☆23Updated 11 years ago
Alternatives and similar repositories for pipemonitor:
Users that are interested in pipemonitor are comparing it to the libraries listed below
- 粗暴 地枚举管理内核的WFP对象。 Manage kernel WFPs in a brutal way.☆26Updated 7 years ago
- Map memory to user space and manipulate user memory, using capmon☆23Updated 6 years ago
- ☆40Updated 5 years ago
- map driver to memory☆25Updated 6 years ago
- An ark tool's driver☆40Updated 7 years ago
- Sysark全称system anti-rootkit,是我学习内核写的工具(2013年的代码,后续不会再更新),里面基本上所有的功能都是用内核实现的。这里只是实现了反rootkit部分功能,作为工具的话,本人觉得还欠完善,但作为学习,或有人需要。目前针对的是XP SP2,…☆27Updated 7 years ago
- x64 Kernel Hooks Detection☆24Updated 8 years ago
- ☆14Updated 6 years ago
- For Example. See Miro's Blog☆30Updated 2 years ago
- Demo List cm/ps/ob/minifilter callback And Patch/Bypass it☆28Updated 7 years ago
- A file system filter, you can do some interesting thing, maybe it's cool.☆56Updated 6 years ago
- ☆23Updated 7 years ago
- x64HOOK库☆18Updated 5 years ago
- Windows NDIS 6.3 Protocol Driver that provides usermode access to an IsoSwitch or CrowdSwitch☆10Updated 6 years ago
- copy of tdifw lib☆10Updated 7 years ago
- 常用代码类☆13Updated 10 years ago
- Basic Injector running on x64 machines that is able to load into x64 AND x86 processes☆21Updated 5 years ago
- ☆30Updated 6 years ago
- 一个32位windows下x86指令集的代码扭曲加密小工具☆32Updated 6 years ago
- ☆27Updated 5 years ago
- ☆28Updated 4 years ago
- windows kernel File redirection☆20Updated 10 years ago
- PDB Explorer 是一个能够查看微软 pdb 文件(Program DataBase,程序数据库)的工具,它能够将 pdb 文件中的 struct、union 及 enum 类型的定义以 C/C++ 的语法显示出来,特别适合 Windows 底层研究人员及 DDK …☆37Updated 9 years ago
- enable libemu run pe file and add some good modify☆14Updated 6 years ago
- a sandbox project by sudami☆17Updated 6 years ago
- ☆35Updated 9 years ago
- just an lite AntiRootkit for interesting☆23Updated 9 years ago
- ☆38Updated 6 years ago
- Windows driver with usermode interface which can hide objects of file-system and registry, protect processes and etc☆16Updated 6 years ago
- windows inlinehook R3 R0☆11Updated 6 years ago