A Linux based Windows compatible user mode kernel
☆59Aug 14, 2009Updated 16 years ago
Alternatives and similar repositories for ring3k
Users that are interested in ring3k are comparing it to the libraries listed below
Sorting:
- Enumerates very, very large directories quickly by directly using kernel syscalls. For POSIX and Windows. WARNING THIS IS OBSOLETE. USE B…☆15Aug 13, 2014Updated 11 years ago
- An analytical debugger programmed in C++, using Qt.☆22May 20, 2012Updated 13 years ago
- bmod parses binaries for modification/patching and disassembles machine code sections.☆12Apr 19, 2018Updated 7 years ago
- Windows Kernel Mode PCRE☆10Feb 4, 2015Updated 11 years ago
- Kernel debugger using Intel VT-x. Designed to be compatible with linux, ucore, windows.☆28Jun 12, 2013Updated 12 years ago
- hypervisor in windows device driver by intel vt☆14Aug 25, 2018Updated 7 years ago
- ☆13Aug 12, 2015Updated 10 years ago
- windows kernel File redirection☆20Sep 21, 2014Updated 11 years ago
- ☆12May 12, 2014Updated 11 years ago
- ☆12Feb 19, 2017Updated 9 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆27May 21, 2014Updated 11 years ago
- Minifilter Driver☆15Feb 10, 2017Updated 9 years ago
- NTrace -- a function boundary tracing tool for Windows user and kernel mode☆22Nov 1, 2013Updated 12 years ago
- Dynamic trace toolkit for Windows☆52Jun 25, 2025Updated 8 months ago
- Windows PE file debugger☆11Aug 30, 2017Updated 8 years ago
- Windows Kernel Driver - Create a driver device in TDI layer of windows kernel to capture network data packets☆36Jul 21, 2014Updated 11 years ago
- Notes my learning steps about Windows-NT☆23May 18, 2017Updated 8 years ago
- Scanning and identifying XOR encrypted PE files in PE resources☆30Jun 22, 2014Updated 11 years ago
- Utility tool to help digitally sign applications (binaries) on Windows.☆13Jun 8, 2015Updated 10 years ago
- Example of intel virtualization extensions usage☆10Dec 15, 2016Updated 9 years ago
- A system call tracer☆10Sep 22, 2014Updated 11 years ago
- The demo on Windows☆21Mar 6, 2016Updated 9 years ago
- Examples for detection of hidden processes on windows☆35Jun 11, 2014Updated 11 years ago
- Maltrace is a simple syscall tracer for Windows implemented through the use of PIN.☆24Apr 10, 2013Updated 12 years ago
- Library for kernel and user mode splicing for Windows (x86 and x64).☆64Oct 29, 2012Updated 13 years ago
- Vulnerable Windows Driver with exploits which were used for demonstration purposes on Hunting and exploiting bugs in kernel drivers prese…☆13Jan 29, 2013Updated 13 years ago
- pass game protect☆12Apr 26, 2014Updated 11 years ago
- OllyCallTrace is a plugin for OllyDbg to trace the call chain of a thread.☆54Nov 4, 2011Updated 14 years ago
- UI application that can compare PE images in memory or in raw PE file☆19Feb 17, 2014Updated 12 years ago
- This is the first software system, which can detect a stealthy hypervisor and calculate several nested ones even under countermeasures.☆87Jun 16, 2015Updated 10 years ago
- ☆27May 27, 2017Updated 8 years ago
- Common Malware Techniques☆13Mar 26, 2023Updated 2 years ago
- [Not work] Deobfuscate obfuscated binaries!☆11Dec 16, 2016Updated 9 years ago
- ☆11Sep 28, 2017Updated 8 years ago
- XFS readonly driver for Windows☆15Jun 30, 2012Updated 13 years ago
- wow64 syscall filter☆13Nov 12, 2014Updated 11 years ago
- Detect the SCI in windows.☆11Mar 23, 2017Updated 8 years ago
- ShellcodeVM☆15Jun 20, 2016Updated 9 years ago
- Samples about Microsoft RPC and native API calls in Windows C☆63Jul 31, 2016Updated 9 years ago