lstaroth / xorstr-securityLinks
Bypass detection from Flare-floss
☆28Updated 2 years ago
Alternatives and similar repositories for xorstr-security
Users that are interested in xorstr-security are comparing it to the libraries listed below
Sorting:
- Windows x64 DLL/Driver manual map injection on a non-present PML4E using physical memory read/writes, direct page table manipulation and …☆72Updated 2 months ago
- ☆144Updated 3 years ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆98Updated 2 years ago
- POC usermode <=> kernel communication via ALPC.☆65Updated last year
- ☆125Updated 2 years ago
- A simple ida python script to find .data ptr☆56Updated 2 years ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆118Updated 3 years ago
- A library to assist with memory & code protection.☆65Updated last year
- DWM overlay without pattern scanning☆58Updated last month
- Expanding Kernel Lazy Importer☆32Updated 2 years ago
- ☆63Updated 3 years ago
- ☆156Updated last year
- Windows X64 mode use seh in manual mapped dll or manual mapped sys☆76Updated 3 years ago
- InfinityHookProMax: Make InfinityHook great great again☆48Updated 2 years ago
- ☆62Updated 3 years ago
- x64/x86 Hooking through VectoredExceptionHandler (PAGE_GUARD method)☆61Updated 2 years ago
- A series of methods used to detect kernel shellcode for tencent game safe race 2024☆45Updated last year
- Example of reading process memory through kernel special APC☆110Updated 2 years ago
- Unknowncheats Magically Optimized Tidy Mapper using nvaudio☆141Updated last year
- Some psuedo snippets from BattlEye's BEDaisy.sys loaded on Rainbow Six: Siege.☆128Updated 3 years ago
- 将驱动映射到会话空间☆38Updated 3 years ago
- ☆147Updated last year
- base for testing☆179Updated last year
- ☆72Updated 3 years ago
- Shows an example of how to implement VT-d/AMD-Vi on Windows☆157Updated 2 years ago
- Example driver on how to use SKLib☆64Updated last year
- Forked LLVM focused on MSVC Compatibility. This version is designed for windows users☆131Updated this week
- This project will give you an example how you can hook a kernel vtable function that cannot be directly called☆83Updated 3 years ago
- Virtual and physical memory hacking library using gigabyte vulnerable driver☆70Updated 2 years ago
- ☆48Updated 3 years ago