kphongagsorn / windows-undocumented-apisLinks
Projects on undocumented windows APIs, a keylogger PoC, and dll injection PoC. Based off of a Defcon workshop
☆35Updated 7 years ago
Alternatives and similar repositories for windows-undocumented-apis
Users that are interested in windows-undocumented-apis are comparing it to the libraries listed below
Sorting:
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 6 years ago
- Bare template for a Kernel Mode Driver☆51Updated 5 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- Clone running process with ZwCreateProcess☆57Updated 4 years ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆52Updated 6 years ago
- UIAccess UAC Bypass using token duplication and keyboard events☆27Updated 5 years ago
- Demos and presentation from SECArmy Village Grayhat 2020☆38Updated 2 years ago
- ☆22Updated 4 years ago
- A ready-made template for a project based on libpeconv.☆48Updated 3 months ago
- [C#]Main.exe < - > [C_DLL] < - > [C_KERNEL] = Memory_Editor via Kernel☆33Updated 5 years ago
- A small library helping to parse commandline parameters (for C/C++)☆57Updated 2 weeks ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆60Updated 9 months ago
- .NET wrapper for dbghelp.dll☆21Updated 5 years ago
- Exploits I've authored☆60Updated 5 years ago
- View handles and object for each object type☆64Updated 5 years ago
- Local OXID Resolver (LCLOR) : Research and Tooling☆35Updated 4 years ago
- A console debugger using DbgX and Terminal.Gui☆30Updated 2 years ago
- Dump certificates from PE files in different formats☆38Updated last year
- A simple POC to demonstrate the power of .NET debugging for injection☆72Updated 4 years ago
- Diff plugin for x64dbg☆31Updated 4 years ago
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆27Updated 6 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆36Updated 4 years ago
- This contains Helpful PYKD (Python Extension for Windbg) scripts☆47Updated 10 years ago
- A set of small utilities, helpers for PIN tracers☆33Updated last year
- Crash Windows 10 up to RS2 from an unprivileged process☆41Updated 7 years ago
- A simple API monitor for Windbg☆63Updated 8 years ago
- Win32 memory leak detector with ETW☆45Updated 7 years ago
- .NET instrumentation framework☆72Updated 7 years ago
- ☆45Updated 6 years ago
- IDA script for vmprotect Windows Api address decoder☆51Updated 4 years ago