kphongagsorn / windows-undocumented-apis
Projects on undocumented windows APIs, a keylogger PoC, and dll injection PoC. Based off of a Defcon workshop
☆34Updated 7 years ago
Alternatives and similar repositories for windows-undocumented-apis:
Users that are interested in windows-undocumented-apis are comparing it to the libraries listed below
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 6 years ago
- A ready-made template for a project based on libpeconv.☆44Updated 4 months ago
- ☆22Updated 4 years ago
- ☆45Updated 6 years ago
- Crash Windows 10 up to RS2 from an unprivileged process☆41Updated 7 years ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆58Updated 6 months ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆52Updated 11 months ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆52Updated 6 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆58Updated 8 years ago
- [C#]Main.exe < - > [C_DLL] < - > [C_KERNEL] = Memory_Editor via Kernel☆32Updated 5 years ago
- Diff plugin for x64dbg☆31Updated 4 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆27Updated 6 years ago
- Demos for Presentation on Windows Runtime Security☆69Updated 6 years ago
- ☆22Updated 4 years ago
- A small library helping to parse commandline parameters (for C/C++)☆54Updated last year
- Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loadi…☆16Updated 7 years ago
- Yet another Windows DLL injector.☆38Updated 3 years ago
- Plugin for x64dbg to generate Yara rules from function basic blocks.☆34Updated 7 years ago
- JITM is an automated tool to bypass the JIT Hooking protection on a .NET sample.☆50Updated 4 years ago
- Dump certificates from PE files in different formats☆38Updated last year
- A console debugger using DbgX and Terminal.Gui☆29Updated 2 years ago
- This repository contains some tools that I have written in the past☆28Updated last year
- IDA script for vmprotect Windows Api address decoder☆51Updated 3 years ago
- ASUSTeK AsIO3 I/O driver unlock☆20Updated 3 years ago
- Three Tiny Examples of Directly Using Vista's NtCreateUserProcess☆85Updated 9 years ago
- Example/starter code for custom Windows application compatibility shims☆32Updated 4 years ago
- A set of small utilities, helpers for PIN tracers☆31Updated last year
- .NET instrumentation framework☆72Updated 7 years ago
- Clone running process with ZwCreateProcess☆57Updated 4 years ago