nccgroup / WindowsPatchDetectorLinks
Experimental Windows .text section Patch Detector
☆22Updated 10 years ago
Alternatives and similar repositories for WindowsPatchDetector
Users that are interested in WindowsPatchDetector are comparing it to the libraries listed below
Sorting:
- PoC for Bypassing UM Hooks By Bruteforcing Intel Syscalls☆39Updated 9 years ago
- ☆16Updated 8 years ago
- Malware Analysis, Anti-Analysis, and Anti-Anti-Analysis☆45Updated 8 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆22Updated 7 years ago
- ☆34Updated 8 years ago
- Exploits pack for the Windows Kernel mode driver HackSysExtremeVulnerableDriver written for educational purposes.☆66Updated 4 years ago
- ☆23Updated 4 years ago
- Malware analyses and helpful scripts☆29Updated 3 years ago
- Public repository for HEVD exploits☆20Updated 7 years ago
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 7 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆57Updated 9 years ago
- ☆46Updated 7 years ago
- Pack required dlls into a single binary that has no imports and makes direct syscalls on Windows☆28Updated 8 years ago
- PCAUSA Rawether for Windows Local Privilege Escalation☆39Updated 8 years ago
- Code Injector Using Code Caves☆15Updated 10 years ago
- A simple tool to view important DLL Characteristics and change DEP and ASLR☆45Updated 7 years ago
- Blog posts☆29Updated 5 years ago
- Experimental: Windows .text section compare - disk versus memory☆15Updated 10 years ago
- ☆10Updated 8 years ago
- Protects and logs suspicious and malicious usage of .NET CSC.exe and Runtime C# Compilation☆25Updated 7 years ago
- public bugs/proof of concepts☆50Updated 4 years ago
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆32Updated 8 years ago
- ☆54Updated 8 years ago
- ☆36Updated 6 years ago
- ☆24Updated 6 years ago
- Control Flow Guard Teleportation demo☆23Updated 6 years ago
- findLoop - find possible encryption/decryption or compression/decompression code☆26Updated 6 years ago
- Sysmon shenanigans☆66Updated 5 years ago
- Resources for the workshop titled "Repacking the unpacker: Applying Time Travel Debugging to malware analysis", given at HackLu 2019☆42Updated 6 years ago
- Scripts targeting specific families☆13Updated 8 years ago