kkent030315 / EvilHooker
Function hooks in Windows NT Kernel
☆21Updated 4 years ago
Alternatives and similar repositories for EvilHooker:
Users that are interested in EvilHooker are comparing it to the libraries listed below
- Intraceptor intercept Windows NT API calls and redirect them to a kernel driver to bypass process/threads handle protections.☆28Updated 2 years ago
- Two PoC of accessing process virtual memory via NT Kernel☆23Updated 3 years ago
- Simplifies the Windows Kernel APIs by making the existing function easier to use, and extends them by creating functions that could possi…☆26Updated 5 months ago
- ASUSTeK AsIO3 I/O driver unlock☆20Updated 3 years ago
- A slightly safer io access library☆12Updated 3 years ago
- Elevate arbitrary MSR writes to kernel execution.☆25Updated last year
- Disk based DMA for ATA and SCSI☆16Updated last year
- detect hypervisor with Nmi Callback☆34Updated 2 years ago
- This is a POC Test project for INTEL CPUs on blocking NMI Entries through the IDT Handler.☆29Updated 3 months ago
- A reflexive driver loader to bypass Windows DSE (featuring a custom PE loader)☆39Updated 6 years ago
- Bypassing kernel patch protection runtime☆19Updated last year
- A packed & protected Module Loader and more, for 64-bit Windows☆28Updated 3 years ago
- x64 Windows implementation of virtual-address to physical-address translation☆41Updated 3 years ago
- Abusing RtlAdjustPrivilege and NtSetInformationProcess to cause a BSOD from usermode☆16Updated 2 years ago
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆42Updated last year
- A poc that abuses Enclave☆36Updated 2 years ago
- ☆12Updated 9 months ago
- Stealthy Injector that leverages a vulnerable driver and other exploits to remain undetected☆36Updated 6 years ago
- ☆30Updated 3 years ago
- Small memory leak PoC that is happening in IopGetDeviceInterfaces☆24Updated 4 years ago
- Hijack NotifyRoutine for a kernelmode thread☆41Updated 2 years ago
- (DEPRECATED) A simple anti-anti debug library for Windows☆29Updated 4 years ago
- x64 Windows privilege elevation using anycall☆20Updated 3 years ago
- ☆15Updated 3 years ago
- An example code of CiGetCertPublisherName☆14Updated 2 years ago
- realExtern.sys driver☆65Updated 4 years ago
- Small class to parse debug info from PEs, download their respective PDBs from the Microsoft Public Symbol Server and calculate RVAs of fu…☆42Updated last year