kphongagsorn / windows-undocumented-apis
Projects on undocumented windows APIs, a keylogger PoC, and dll injection PoC. Based off of a Defcon workshop
☆34Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for windows-undocumented-apis
- Demos for Presentation on Windows Runtime Security☆70Updated 6 years ago
- Windows GPU rootkit PoC by Team Jellyfish☆35Updated 9 years ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆51Updated 6 years ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆57Updated 3 months ago
- Windows x64 Process Scanner to detect application compatability shims☆36Updated 6 years ago
- Demos and presentation from SECArmy Village Grayhat 2020☆36Updated last year
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆27Updated 6 years ago
- A local copy of Alex Ionescu's seemingly abandoned native-nt-toolkit project containing knowledge inherited from the ReactOS project.☆53Updated 5 years ago
- A small library helping to parse commandline parameters (for C/C++)☆53Updated last year
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- [C#]Main.exe < - > [C_DLL] < - > [C_KERNEL] = Memory_Editor via Kernel☆31Updated 5 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- ☆45Updated 6 years ago
- ☆21Updated 3 years ago
- UIAccess UAC Bypass using token duplication and keyboard events☆25Updated 5 years ago
- ☆22Updated 4 years ago
- Neutralize KEPServerEX anti-debugging techniques☆31Updated last year
- Local OXID Resolver (LCLOR) : Research and Tooling☆33Updated 3 years ago
- A ready-made template for a project based on libpeconv.☆41Updated last month
- A simple API monitor for Windbg☆62Updated 7 years ago
- Miscellaneous Code and Docs☆77Updated 11 months ago
- Decrement Windows Kernel for fun and profit☆39Updated 6 years ago
- Simple tool that allows you to have multiple Just-In-Time debuggers at once.☆72Updated 2 months ago
- Diff plugin for x64dbg☆31Updated 3 years ago
- Exploits I've authored☆59Updated 5 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆129Updated 4 years ago
- APIInfo Plugin (x86) - A Plugin For x64dbg☆49Updated 6 years ago
- Rekall Memory Forensic Framework☆29Updated 5 years ago