nblog / Win32-Hook-Demo
reveal and detect of common hooks under win32
☆13Updated 4 years ago
Alternatives and similar repositories for Win32-Hook-Demo:
Users that are interested in Win32-Hook-Demo are comparing it to the libraries listed below
- get ntdll syscall index☆12Updated 4 years ago
- viewing page boundaries of pages with PAGE_NOACCESS protection reveals the presence of x64dbg.☆23Updated 8 years ago
- eac memory sig maker☆12Updated 3 years ago
- Ready-to-use headers for Windows Kernel SSDT indices☆11Updated 5 years ago
- ☆15Updated 4 years ago
- x64 assembler library☆31Updated 10 months ago
- Small class to parse debug info from PEs, download their respective PDBs from the Microsoft Public Symbol Server and calculate RVAs of fu…☆44Updated 2 years ago
- A small header file mapping status codes passed to KiExceptionDispatch before KiPreprocessFault to individual CPU faults.☆13Updated 6 years ago
- Intel-VT-x/Hook Msr Build and Replace System Server Description Table.☆14Updated last month
- Disable threat tracing from the kernel..☆13Updated 3 years ago
- pdb's function and global vars to offset☆10Updated 2 years ago
- ☆27Updated last year
- P2C Loader based on blackbone, used by isolation.top and others.☆14Updated 7 years ago
- x64 Kernel Hooks Detection☆24Updated 8 years ago
- A helper class for hardware breakpoints☆12Updated 5 years ago
- Open Anti Cheat☆27Updated 2 years ago
- Wow64 syscall hook☆40Updated 7 years ago
- Remote memory library in C++17.☆31Updated 6 years ago
- Detour library (x64 and x86 compatible)☆12Updated 4 years ago
- Map memory to user space and manipulate user memory, using capmon☆23Updated 6 years ago
- Driver Loader/BE Bypass/Win Malware(lol)☆34Updated 5 years ago
- Very tiny and selective implementation of STL for Windows NT kernel mode drivers☆18Updated 3 years ago
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- A simple kernel mode driver that hooks some values at the KUSER_SHARED_DATA structure.☆26Updated 5 years ago
- ☆48Updated 6 years ago
- Some eternal WIP stuff :)☆16Updated last month
- A class to gather information about a process, its threads and modules.☆24Updated 5 years ago
- Translates WinDbg "dt" structure dump to a C structure☆13Updated 4 years ago
- Some crazy PE executables protection kernel driver☆18Updated 5 years ago
- Decoder for VMProtect hwids☆17Updated 2 years ago