mobdk / WinSpoofLinks
Use TpAllocWork, TpPostWork and TpReleaseWork to execute machine code
☆22Updated 2 years ago
Alternatives and similar repositories for WinSpoof
Users that are interested in WinSpoof are comparing it to the libraries listed below
Sorting:
- C code to enable ETW tracing for Dotnet Assemblies☆31Updated 2 years ago
- ☆54Updated 2 years ago
- One gate to all syscalls!☆23Updated 3 years ago
- Ntdll Unhooking POC☆19Updated 2 years ago
- BOF implementation of Adopt. Spawns a process from a process. Can sometimes be used to run a session > 0 process from session 0.