jschicht / SectorIo
Kernel mode driver for writing to physical disk with SL_FORCE_DIRECT_WRITE
☆22Updated 10 years ago
Related projects ⓘ
Alternatives and complementary repositories for SectorIo
- User-mode program parsing logs created by HyperPlatform☆17Updated 8 years ago
- An API Monitor based on Instrumentation☆42Updated 6 years ago
- Various WinDbg extensions and scripts☆31Updated 6 years ago
- Analyze PatchGuard☆53Updated 6 years ago
- Wow64 syscall hook☆40Updated 7 years ago
- just an lite AntiRootkit for interesting☆23Updated 8 years ago
- Spoof Windows Test Signing Mode☆29Updated 6 years ago
- Windows Kernel Driver - Create a driver device in TDI layer of windows kernel to capture network data packets☆36Updated 10 years ago
- ☆32Updated 4 years ago
- Kinject - kernel dll injector, currently available in x86 version, will be updated to x64 soon.☆32Updated 9 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆24Updated 10 years ago
- OpenSrc projects; common multiprojects headers store to ./Common/*category*/☆48Updated 10 years ago
- A command line tool to load and unload a device driver.☆44Updated 7 years ago
- A simple ransomware defender.It uses minifilter to filt "rewrite" and "delete" events in kernel.And it handles event in user mode.☆27Updated 6 years ago
- Some of example code that I have collected while learning☆10Updated 8 years ago
- kernel-mode TDI client which can send and receive HTTP requests☆55Updated 6 years ago
- Helper utility for debugging windows PE/PE+ loader.☆50Updated 9 years ago
- Maltrace is a simple syscall tracer for Windows implemented through the use of PIN.☆23Updated 11 years ago
- Simple command line version of Sysinternals WinObj. Currently just lists object names and types given an object manager directory.☆19Updated last year
- POC of sysenter x64 LSTAR MSR hook☆38Updated 10 years ago
- WinDbg debugger extension library providing various tools to analyse, dump and fix (restore) Microsoft Portable Executable files for both…☆81Updated 2 months ago
- Plain project for usege with github/zer0mem/common.git☆48Updated 10 years ago
- Full reversing of the Microsoft Auxiliary Windows API Library and ported to C☆23Updated last year
- Open Source Libraries Collection☆24Updated 8 years ago
- old code from 2007/2008 which uses split TLB to trace OEP☆16Updated 6 years ago
- An ark tool's driver☆39Updated 7 years ago
- Anti-Anti-VM solution via Windows Driver☆54Updated 6 years ago
- Windows driver with usermode interface which can hide objects of file-system and registry, protect processes and etc☆15Updated 6 years ago