kphongagsorn / windows-undocumented-apis
Projects on undocumented windows APIs, a keylogger PoC, and dll injection PoC. Based off of a Defcon workshop
☆35Updated 7 years ago
Alternatives and similar repositories for windows-undocumented-apis
Users that are interested in windows-undocumented-apis are comparing it to the libraries listed below
Sorting:
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- UIAccess UAC Bypass using token duplication and keyboard events☆27Updated 5 years ago
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 6 years ago
- A ready-made template for a project based on libpeconv.☆48Updated 2 months ago
- ☆36Updated 6 years ago
- ☆22Updated 4 years ago
- ☆45Updated 6 years ago
- Clone running process with ZwCreateProcess☆57Updated 4 years ago
- Crash Windows 10 up to RS2 from an unprivileged process☆41Updated 7 years ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆60Updated 8 months ago
- Yet another Windows DLL injector.☆39Updated 3 years ago
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆27Updated 6 years ago
- Bare template for a Kernel Mode Driver☆51Updated 5 years ago
- .NET instrumentation framework☆72Updated 7 years ago
- A hooking library with a MinHook-like API and a Detours-like implementation, with support for the x86, x64, and ARM64 platforms☆19Updated 3 weeks ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆72Updated last year
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆58Updated 8 years ago
- CTF writeups☆35Updated 6 months ago
- Managed wrappers around the Windows API and some Native API☆35Updated 6 years ago
- View handles and object for each object type☆64Updated 5 years ago
- Miscellaneous Code and Docs☆81Updated last year
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- .NET library for hooking and dumping Clr☆42Updated 11 months ago
- DLL Injection Library & Tools☆72Updated 8 years ago
- Windbg extension that allows you analyze Control Flow Guard map☆35Updated 3 years ago
- A simple API monitor for Windbg☆63Updated 8 years ago
- A small library helping to parse commandline parameters (for C/C++)☆57Updated last year
- A specialized C# memory-accessing library☆43Updated 6 years ago
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆38Updated 3 years ago
- PoC for detecting and dumping process hollowing code injection☆51Updated 6 years ago