mrexodia / perfect-dll-proxy
Perfect DLL Proxying using forwards with absolute paths.
☆254Updated last month
Related projects ⓘ
Alternatives and complementary repositories for perfect-dll-proxy
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆178Updated 3 weeks ago
- Admin to Kernel code execution using the KSecDD driver☆236Updated 7 months ago
- Generate a proxy dll for arbitrary dll☆145Updated last month
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆115Updated 2 months ago
- For when DLLMain is the only way☆353Updated 3 weeks ago
- Process Injection using Thread Name☆241Updated 2 months ago
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆260Updated 10 months ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆237Updated 2 years ago
- Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths☆304Updated 3 months ago
- PoC Anti-Rootkit/Anti-Cheat Driver.☆160Updated 2 months ago
- Single header version of System Informer's phnt library.☆186Updated this week
- This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret …☆231Updated last year
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆226Updated 3 months ago
- Debugger Anti-Detection Benchmark☆291Updated 11 months ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated 10 months ago
- Collection of hypervisor detections☆189Updated last month
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆261Updated last month
- Call stack spoofing for Rust☆299Updated 2 months ago
- Implementation of Advanced Module Stomping and Heap/Stack Encryption☆210Updated last year
- Using Windows' own bootloader as a shim to bypass Secure Boot☆142Updated 4 months ago
- A small x64 library to load dll's into memory.☆424Updated last year
- A universal binary patching dll.☆80Updated last month
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆267Updated last year
- RISC-V Virtual Machine☆204Updated 3 weeks ago
- Patching "signtool.exe" to accept expired certificates for code-signing.☆271Updated 4 months ago
- Dont Call Me Back - Dynamic kernel callback resolver. Scan kernel callbacks in your system in a matter of seconds!☆224Updated 4 months ago
- Various Process Injection Techniques☆143Updated 2 years ago
- Bypassing PatchGuard on modern x64 systems☆245Updated last year
- ☆210Updated last year
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆154Updated last year