malware-unicorn / pteroioctl-hook
A driver to implement IOCTL hooking
☆23Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for pteroioctl-hook
- Exports monitoring plugin for x64dbg☆20Updated last year
- ☆29Updated 2 years ago
- ☆15Updated last year
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆18Updated last month
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆48Updated 3 years ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- WinXPSP2.Cermalus on stereoids, supporting all 32 bits Windows version. Windows Kernel Virus stuff for noobs☆16Updated last year
- Dump PDB Symbols including support for Bochs Debugging Format (with wine support)☆14Updated last year
- A demonstration of hooking into the VMProtect-2 virtual machine☆17Updated last year
- Small project to generate fake DLLs based on an executable's import table☆23Updated 4 years ago
- Some drivers I've written while solving exercises from Practical Reverse Engineering☆14Updated 2 years ago
- .lib file for linking against the NT CRT☆20Updated 2 years ago
- ☆16Updated 2 years ago
- vdk is a set of utilities used to help with exploitation of a vulnerable driver.☆39Updated 2 years ago
- Windows Minidump loader for Ghidra☆19Updated 2 years ago
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆36Updated 2 years ago
- Binary Ninja plugin for automating VMProtect analysis☆57Updated last year
- Windows driver template, using C++20 & cmake & GithubActions☆19Updated 3 months ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆61Updated last year
- A way to detect DBI frameworks, Debuggers and VMs.☆22Updated 4 years ago
- This is a ring -1 header framework in order to simplify the creation of hypervisors on SVM☆22Updated last year
- Windows kernel driver template for cmkr and llvm-msvc.☆33Updated 11 months ago
- Fix VMProtect 3.xx (tested 3.0.9 to 3.5.0)☆16Updated 2 years ago
- ☆30Updated 2 years ago
- Proof-of-concept game using VBS enclaves to protect itself from cheating☆21Updated 2 weeks ago
- Extensions for x64dbg written in Rust: Telescope and Unicorn powered disassembly☆24Updated last year
- ☆21Updated 4 months ago
- Triton based symbolic emulator☆16Updated 2 years ago