mike1k / HookHunterLinks
Analyze patches in a process
☆256Updated 4 years ago
Alternatives and similar repositories for HookHunter
Users that are interested in HookHunter are comparing it to the libraries listed below
Sorting:
- Kernel LdrLoadDll injector☆261Updated 6 years ago
- Vectored Exception Handling Hooking Class☆161Updated 6 years ago
- C++ library for parsing and manipulating PE files statically and dynamically.☆88Updated last year
- Elevate a process to be a protected process☆153Updated 5 years ago
- Browse Page Tables on Windows (Page Table Viewer)☆215Updated 3 years ago
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆354Updated 3 years ago
- Simple x86/x86_64 instruction level obfuscator based on a basic SBI engine☆274Updated 2 years ago
- x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code☆206Updated 4 years ago
- Load your driver like win32k.sys☆254Updated 3 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆138Updated 3 years ago
- ☆153Updated 5 years ago
- x86 Binary Code Virtualization Tool☆220Updated 6 months ago
- A customizable process dumper.☆142Updated 6 years ago
- Manual DLL Injector using Thread Hijacking.☆238Updated 7 years ago
- Easy Anti PatchGuard☆224Updated 4 years ago
- x86 PE Mutator☆225Updated 2 years ago
- Tutorial & a blog post that demonstrate how to code a Windows driver to inject a custom DLL into all running processes. I coded it from s…☆138Updated 4 years ago
- Windows inline hooking tool.☆282Updated 6 years ago
- Asynchronous Procedure Calls☆236Updated 4 years ago
- A modern c++ implementation of windows heavens gate☆229Updated 4 years ago
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆145Updated 3 years ago
- Debugger Anti-Detection Benchmark☆356Updated 2 weeks ago
- Obfuscate calls to imports by patching in stubs☆70Updated 4 years ago
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.☆309Updated 5 years ago
- PE-Dump-Fixer☆110Updated 5 years ago
- ☆169Updated 8 years ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆144Updated last year
- Global user-mode hooking framework, based on AppInit_DLLs. The goal is to allow you to rapidly develop hooks to inject in an arbitrary pr…☆177Updated 3 years ago
- Code Injection, Inject malicious payload via pagetables pml4.☆242Updated 4 years ago
- Ghetto user mode emulation of Windows kernel drivers.☆146Updated 10 months ago