kkent030315 / EvilHooker
Function hooks in Windows NT Kernel
☆22Updated 4 years ago
Alternatives and similar repositories for EvilHooker:
Users that are interested in EvilHooker are comparing it to the libraries listed below
- Intraceptor intercept Windows NT API calls and redirect them to a kernel driver to bypass process/threads handle protections.☆29Updated 2 years ago
- This is a POC Test project for INTEL CPUs on blocking NMI Entries through the IDT Handler.☆43Updated 6 months ago
- Disk based DMA for ATA and SCSI☆23Updated last year
- Disable NMI Callbacks with Kernelmode Driver☆18Updated 2 years ago
- Register a callback from a Manually mapped kernel module☆16Updated 3 years ago
- ☆14Updated 4 years ago
- Custom KiSystemStartup, can be used to modificate kernel before boot.☆51Updated 3 years ago
- Illustrates the concept of return address spoofing, and how it is used.☆13Updated 4 years ago
- A poc that abuses Enclave☆38Updated 2 years ago
- Bypassing kernel patch protection runtime☆20Updated 2 years ago
- a dumb rpm/wpm example driver☆15Updated 3 years ago
- Swap control lioctl with trampoline recording in the .text section☆15Updated 3 years ago
- Driver shared section communication☆44Updated last month
- C++ console logging library (fmt wrapper)☆17Updated 5 years ago
- Two PoC of accessing process virtual memory via NT Kernel☆22Updated 3 years ago
- detect hypervisor with Nmi Callback☆34Updated 2 years ago
- Memory Guard Library☆11Updated 4 years ago
- Old way for blocking NMI interrupts☆26Updated 2 years ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆42Updated last year
- A simple MmCopyMemory hook.☆37Updated 2 years ago
- ☆11Updated 11 months ago
- search for a driver/dll module that has a wanted section bigger than the size of your image☆19Updated 3 years ago
- A slightly safer io access library☆13Updated 3 years ago
- Stealthy Injector that leverages a vulnerable driver and other exploits to remain undetected☆36Updated 6 years ago
- a driver to enumerate registered pnp callbacks for a particular interface class based on reversal of IoRegisterPlugPlayNotification☆11Updated last year
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆33Updated 5 months ago
- Detour library (x64 and x86 compatible)☆12Updated 4 years ago
- UM-KM Communication using registry callbacks☆39Updated 4 years ago
- Mapping your code on a 0x1000 size page☆72Updated 2 years ago
- POC Hook of nt!HvcallCodeVa☆51Updated last year