lcsig / API-Hooking
Different API Hooking Techniques - Ring3 (Detours, Trampoline, IAT and EAT) for both, x64 and x32 PE files - Since 2014.
☆16Updated 3 months ago
Alternatives and similar repositories for API-Hooking:
Users that are interested in API-Hooking are comparing it to the libraries listed below
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆60Updated 7 months ago
- NO WriteProcessMemory CreateRemoteThread APIs call shellcode injection☆28Updated 5 years ago
- A simple program to obfuscate code written in cpp.☆48Updated 11 months ago
- ☆31Updated 4 years ago
- ☆26Updated 5 years ago
- A stack and register based virtual machine which can compile and execute arbitrary code in runtime☆44Updated last month
- Call NtCreateUserProcess directly as normal.☆71Updated 2 years ago
- Static Library For Windows Drivers☆33Updated 2 months ago
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Updated 2 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆105Updated 2 years ago
- A library with four different methods to execute shellcode in a process☆24Updated 5 years ago
- Example of hijacking system calls via function pointer tables☆31Updated 3 years ago
- direct systemcalls with a modern c++20 interface.☆42Updated 2 years ago
- Dynamically generated obfuscated jumps and/or function calls☆35Updated 2 years ago
- sc4cpp is a shellcode framework based on C++☆88Updated 3 years ago
- Record & prevent file deletion in kernel mode☆42Updated 4 years ago
- Compile-Time Calls Obfuscator for C++14+☆43Updated last year
- ☆65Updated 6 years ago
- IAT-Obfuscation to make static analysis of executable harder.☆42Updated 3 years ago
- NtCreateUserProcess with CsrClientCallServer for mainstream Windows x64 version☆30Updated 9 months ago
- An extended proof-of-concept for the CVE-2021-21551 Dell ‘dbutil_2_3.sys’ Kernel Exploit☆24Updated 3 years ago
- ☆52Updated 2 years ago
- Protected Process Light Library☆18Updated 4 years ago
- PEBFake(修改PEB 伪装当前进程路径、参数等)☆51Updated 4 years ago
- CVE-2022-3699 with arbitrary kernel code execution capability☆70Updated 2 years ago
- Ida pro plugin. The antiVM aims to quickly identify anti-virtual machine and anti-sandbox behavior. This can speed up malware analysis.☆41Updated 2 years ago
- Free(or force?)file and delete it☆12Updated 6 years ago
- VT Hook☆46Updated 9 months ago
- windows rpc 使用MIDL+RPC实现HelloWorld☆23Updated 7 years ago
- Injector with kernel power☆16Updated 4 years ago