mgeeky / PE-library
Lightweight Portable Executable parsing library and a demo peParser application.
☆80Updated 2 years ago
Alternatives and similar repositories for PE-library:
Users that are interested in PE-library are comparing it to the libraries listed below
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago
- Library for using direct system calls☆35Updated 3 months ago
- An example of a client and server using Windows' ALPC functions to send and receive data.☆96Updated 3 months ago
- Debug Print viewer (user and kernel)☆66Updated last year
- A simple password-based PE encryptor for Windows 32-bit executables.☆52Updated 4 months ago
- a ntdll.h head file which download from network, and fix all found problems by me.☆32Updated 4 months ago
- Add an empty section to a PE file☆51Updated 7 years ago
- A ready-made template for a project based on libpeconv.☆48Updated 2 months ago
- Hook all callbacks which are registered with LdrRegisterDllNotification☆86Updated last month
- Collection of DLL function export forwards for DLL export function proxying☆97Updated last year
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- Standalone program to download PDB Symbol files for debugging without WDK☆76Updated 5 years ago
- Position-idependent Windows DLL loader based on ReflectiveDLL project.☆97Updated 6 years ago
- Code Injection technique written in cpp language☆31Updated 7 years ago
- c++ implementation of windows heavens gate☆68Updated 4 years ago
- LSASS INJECTOR☆35Updated 6 years ago
- Static library and headers for linking your software with ntdll.dll☆32Updated 5 years ago
- A quick-and-dirty anti-hook library proof of concept.☆103Updated 6 years ago
- Elevate arbitrary MSR writes to kernel execution.☆35Updated last year
- Resolve DOS MZ executable symbols at runtime☆95Updated 3 years ago
- A driver to intercept low level windows events☆63Updated 5 years ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆63Updated 8 months ago
- Demo service that runs in svchost.exe☆79Updated 7 years ago
- Header only library for obfuscation import winapi functions.☆40Updated 2 months ago
- Code injection by hijacking threads in Windows 32-bit applications☆43Updated 6 years ago
- Windows kernel driver encryption library, support base64, aes-256, rsa-2048 and higher, ecc-256, single file, minimal dependence, support…☆21Updated 3 years ago
- This is the P.O.C source for hooking the system calls on Windows 10 (1903) using it's dynamic trace feature weakness☆51Updated 5 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆76Updated 14 years ago
- A simple tool for detecting memory modifications to Windows API.☆22Updated 4 months ago
- C++ library for low-level Windows development☆74Updated last year