nemesisqp / al-khaser
Al-khaser is a PoC malware with good intentions that aimes to stress your malware analysis / sandbox environement
☆31Updated 10 years ago
Alternatives and similar repositories for al-khaser:
Users that are interested in al-khaser are comparing it to the libraries listed below
- Manual PE image mapper☆62Updated 11 years ago
- x64 syscall caller in C++.☆85Updated 6 years ago
- A documented Windows x64 bit Usermode Injector that works via hooking IAT and hijacking its threads to execute shellcode.☆63Updated last year
- This is a simple mutation engine. It does not have many features and you have to add actual mutation, when you want to use it - It does m…☆34Updated 7 years ago
- Automated Integration of anti-Reversing methods in PE executables☆48Updated 6 years ago
- An automatic tool for fixing dumped PE files☆41Updated 4 years ago
- Elevate a process to be a protected process☆144Updated 5 years ago
- Disable Driver Callbacks☆99Updated 7 years ago
- BetaShield Windows x86 Ring3 Anticheat v2☆37Updated 8 years ago
- Kernel mode driver loader, injecting into the windows kernel, Rootkit. Driver injections.☆47Updated 10 years ago
- Hiding x32/x64 Modules/DLLs using PEB☆62Updated 9 years ago
- A sample on how to inject a DLL from a kernel driver☆61Updated 8 years ago
- Capcom wrapper with safety in mind.☆80Updated 6 years ago
- disable most common windowsx64 systems patchguard☆84Updated 6 years ago
- reverse engineering of bedaisy.sys (battleyes kernel driver) - Aki2k/BEDaisy☆66Updated 4 years ago
- A quick-and-dirty anti-hook library proof of concept.☆102Updated 6 years ago
- Simple PE Packer Which Encrypts .text Section☆49Updated 7 years ago
- Recreation of GetProcAddress without external dependencies on Windows Libraries☆89Updated 8 years ago
- Resolve DOS MZ executable symbols at runtime☆93Updated 3 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆75Updated 13 years ago
- Code injection by hijacking threads in Windows 32-bit applications☆43Updated 6 years ago
- Dump system call codes, names, and offsets from Ntdll.dll☆75Updated last year
- (DEPRECATED) A simple anti-anti debug library for Windows☆29Updated 4 years ago
- scans through physical memory and paging tables in kernel mode☆106Updated 4 years ago
- BattlEye x64 usermode injector☆64Updated 5 years ago
- Obfuscate calls to imports by patching in stubs☆65Updated 3 years ago
- Example Windows Kernel-mode Driver which enumerates running processes.☆55Updated 2 years ago
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆68Updated 5 years ago