mq1n / hSonic
New handle stealing technique for windows apps
☆12Updated 7 years ago
Alternatives and similar repositories for hSonic:
Users that are interested in hSonic are comparing it to the libraries listed below
- ☆14Updated 6 years ago
- NT reversal☆25Updated 6 years ago
- P2C Loader based on blackbone, used by isolation.top and others.☆14Updated 7 years ago
- ice9 - is anticheat based on usermode tricks and undocumented methods , builded as dll for loading trought the shibari framework☆19Updated 3 weeks ago
- MazzCrypt - You won't ever get caught. A [was-private] polymorphic source code parser to randomize executables. Inspired by PolyLoader by…☆12Updated 8 years ago
- Dll injector POC for new handle stealing technique☆20Updated 7 years ago
- anti-cheat based on user-mode tricks and undocumented methods☆22Updated 7 years ago
- Spoof Windows Test Signing Mode☆29Updated 6 years ago
- ☆17Updated 4 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆25Updated 10 years ago
- easy to use vtable hook with RTTI support☆23Updated 5 years ago
- win32/x64 obfuscate framework☆32Updated 5 years ago
- Driver Loader/BE Bypass/Win Malware(lol)☆34Updated 5 years ago
- Shareds for kernel developement☆27Updated 11 years ago
- Software Distribution Service☆12Updated 9 years ago
- Memory Guard Library☆11Updated 4 years ago
- viewing page boundaries of pages with PAGE_NOACCESS protection reveals the presence of x64dbg.☆23Updated 8 years ago
- x64 Kernel Hooks Detection☆24Updated 8 years ago
- ☆15Updated 4 years ago
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- Stealthy Injector that leverages a vulnerable driver and other exploits to remain undetected☆36Updated 6 years ago
- LoadLibrary, GetModuleHandle and GetProcAddress calls for remote processes☆22Updated 10 years ago
- x64 assembler library☆31Updated 8 months ago
- My take on the capcom driver vulnerability☆27Updated 7 years ago
- Makes drivers less sucky to manage from usermode.☆11Updated 8 years ago
- simply manual map any system image☆16Updated 4 years ago
- bypass CRC☆11Updated 6 years ago
- UI application that can compare PE images in memory or in raw PE file☆17Updated 11 years ago
- Contains various pintools to supplement the Intel DBI framework☆12Updated 9 years ago
- A driverless driver that is supposed to be manually mapped, usually by using TDL exploit. The driver shows how to read/write to any proce…☆21Updated 7 years ago