momo5502 / hypervisor
๐งช Hypervisor with EPT hooking support.
โ207Updated last month
Alternatives and similar repositories for hypervisor:
Users that are interested in hypervisor are comparing it to the libraries listed below
- alternative smm driver for ryzen motherboardsโ137Updated 5 months ago
- Collection of hypervisor detectionsโ226Updated 6 months ago
- Minimalistic AMD-V/SVM hypervisor with memory introspection capabilitiesโ247Updated last month
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.โ276Updated last year
- Debugger Anti-Detection Benchmarkโ324Updated last year
- VAC3 (Valve Anti-Cheat 3) module emulatorโ97Updated 4 years ago
- Browse Page Tables on Windows (Page Table Viewer)โ196Updated 2 years ago
- Emulate Drivers in RING3 with self context mapping or unicornโ333Updated 2 years ago
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.โ267Updated 8 months ago
- Hooking kernel functions by abusing alignmentโ240Updated 4 years ago
- 09/2021 reversal of EasyAntiCheat driverโ213Updated 3 years ago
- IDA Pro plugin to make bitfield accesses easier to grepโ232Updated last month
- โ163Updated this week
- SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.โ375Updated 4 years ago
- โ139Updated 4 years ago
- ๐ช Different aproaches to detecting EPT hooksโ102Updated 2 years ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.โ586Updated 2 months ago
- ๐จ Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.โ98Updated 11 months ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.โ127Updated 3 years ago
- Ghetto user mode emulation of Windows kernel drivers.โ132Updated 5 months ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.โ274Updated 5 months ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasksโ345Updated 5 months ago
- A customizable process dumper.โ138Updated 5 years ago
- A mapper that maps shellcode into loaded large page driversโ264Updated 2 years ago
- C++ library for parsing and manipulating PE files statically and dynamically.โ86Updated last year
- Rusty Hypervisor - Windows UEFI Blue Pill Type-1 Hypervisor in Rust (Codename: Illusion)โ253Updated 6 months ago
- Windows inline hooking tool.โ251Updated 6 years ago
- x86 PE Mutatorโ216Updated 2 years ago
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.โ284Updated 4 years ago
- Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!โ331Updated 5 months ago