Detects if a Kernel mode debugger is active by reading the value of KUSER_SHARED_DATA.KdDebuggerEnabled. It is a high level and portable implementation between 32 and 64-bit architectures.
☆23Sep 18, 2017Updated 8 years ago
Alternatives and similar repositories for IsKernelDebuggerPresent
Users that are interested in IsKernelDebuggerPresent are comparing it to the libraries listed below
Sorting:
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆27May 21, 2014Updated 11 years ago
- 给windows窗口全局添加一些功能。☆21May 1, 2019Updated 6 years ago
- Simple Demo of using Windows Hypervisor Platform☆29Jul 14, 2025Updated 7 months ago
- Detect removed thread from PspCidTable.☆75Mar 18, 2022Updated 3 years ago
- Communication via callback☆73Oct 9, 2019Updated 6 years ago
- ☆14May 1, 2021Updated 4 years ago
- ☆29Jan 15, 2021Updated 5 years ago
- core of pkn game hacking project. Including mainly for process management, memory management, and DLL injecttion. Also PE analysis, windo…☆68Mar 2, 2019Updated 6 years ago
- easy to use vtable hook with RTTI support☆23Nov 12, 2019Updated 6 years ago
- A simple example how to decrypt kernel debugger data block☆32Feb 8, 2021Updated 5 years ago
- Example of making debugger using Hardware Breakpoint + VEH☆18May 13, 2021Updated 4 years ago
- ☆39Oct 29, 2020Updated 5 years ago
- kernel-mode TDI client which can send and receive HTTP requests☆56Jun 9, 2018Updated 7 years ago
- a demo for x86/x64's paging memory management learning, convert a virtual address from ring3 to physical address in ring0☆19Aug 26, 2017Updated 8 years ago
- ☆23Oct 28, 2020Updated 5 years ago
- Intel Virtualization Technology demo☆73Oct 15, 2016Updated 9 years ago
- Map memory to user space and manipulate user memory, using capmon☆24Nov 3, 2018Updated 7 years ago
- A simple DLL that can intercept HID messages and pass them on to the real HID DLL, while logging the data.☆22Oct 3, 2014Updated 11 years ago
- driver interface with dll-injection capabilities☆28Nov 5, 2020Updated 5 years ago
- Network monitor for Linux☆13Aug 11, 2019Updated 6 years ago
- Stealthy Injector that leverages a vulnerable driver and other exploits to remain undetected☆37Dec 10, 2018Updated 7 years ago
- Kernel mode to user mode injector☆11Mar 31, 2020Updated 5 years ago
- NASM listing to shellcode converter☆14May 6, 2018Updated 7 years ago
- Windows device tree walker☆15Sep 19, 2018Updated 7 years ago
- Demonstrate the new FileDispositionInfoEx behavior☆15Nov 6, 2017Updated 8 years ago
- 新的注入方式☆11Sep 30, 2018Updated 7 years ago
- Assembly code to use for Windows kernel shellcode to edit winlogon.exe ACL☆13Mar 6, 2017Updated 8 years ago
- Data and structures regarding the research done on WdFilter☆12Apr 15, 2020Updated 5 years ago
- An minifilter-based transparent encryptor on Windows.☆30Feb 27, 2017Updated 9 years ago
- AllMemPro☆46Jan 15, 2018Updated 8 years ago
- C++编写的Com组件,实现了内存读写、窗口控制、输入模拟、文本编码、颜色拾取、文件读写、正则转换、XML读写等功能☆22Feb 20, 2017Updated 9 years ago
- A kernel mode Windows rootkit in development.☆49Dec 31, 2021Updated 4 years ago
- Shareds for kernel developement☆29Dec 23, 2013Updated 12 years ago
- Windows system spy for Mouse, Keyboard and Gamepad(Joystick).☆15Jul 6, 2022Updated 3 years ago
- Driver demonstrating how to register a DPC to asynchronously wait on an object☆50Jan 15, 2021Updated 5 years ago
- 基于WinDivert实现的一个包过滤与截断程序☆13Jul 22, 2018Updated 7 years ago
- Inject dll to process in driver☆10Aug 27, 2024Updated last year
- Simple demo of accessing System Management BIOS in UEFI environment.☆14Oct 13, 2020Updated 5 years ago
- A windows kernel driver to Block symbolic link exploit used for privilege escalation.☆15Jul 30, 2020Updated 5 years ago