not1cyyy / KiroshiLinks
an IDA Pro Plugin to detect common Anti-Cheat Artifacts
☆87Updated 3 weeks ago
Alternatives and similar repositories for Kiroshi
Users that are interested in Kiroshi are comparing it to the libraries listed below
Sorting:
- Kernel anti-cheat for protecting software.☆109Updated 3 months ago
- Yet another IDA Pro/Home plugin for deobfuscating stack strings☆117Updated 3 weeks ago
- Experiment with PAGE_GUARD protection to hide memory from other processes☆54Updated last year
- Kernel Level NMI Callback Blocker☆154Updated 4 months ago
- Hijacking Hyper-V at Runtime with DDMA☆76Updated 5 months ago
- An AI-powered assistant for IDA 9.0+ to accelerate reverse engineering of C++ games.☆222Updated last month
- Kernel ReClassEx☆66Updated 2 years ago
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆137Updated last year
- This is an EfiGuard BootLoader that can boot EfiGuard from Usermode with no USB or Setup as a Single Executable with automatic File Dumpi…☆68Updated 4 months ago
- Hooking Windows' exception dispatcher to protect process's PML4☆223Updated last year
- Windows 11 24H2-25H2 Runtime PatchGuard Bypass☆239Updated 2 months ago
- Abusing DDMA alongside Copy On Write for Cross Process Code Execution for a 3000$ Bug Bounty☆82Updated 3 weeks ago
- A simple ida python script to find .data ptr☆56Updated 2 years ago
- A devirtualization engine for Themida.☆105Updated last year
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆47Updated 2 years ago
- PoC kernel to usermode injection☆103Updated last year
- ntoskrnl .data hooks for UM-KM communication☆53Updated last year
- Windows x64 DLL/Driver manual map injection on a non-present PML4E using physical memory read/writes, direct page table manipulation and …☆81Updated 4 months ago
- Simple IDA Pro plugin to download Unity debug symbols from their symbol server☆82Updated last year
- Attempts to decrypt JM Xorstr in some x64 binaries☆59Updated 2 years ago
- Binary rewriter for 64-bit PE files.☆99Updated last year
- ☆83Updated last year
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆48Updated 4 months ago
- DSE & PG bypass via BYOVD attack☆77Updated 6 months ago
- nmi stackwalking + module verification☆155Updated 2 years ago
- VMProtect 3.5+ dynamic import resolver☆19Updated last year
- Using MMIO (Memory-Mapped I/O) to read TPM 2.0 public Endorsement Key.☆52Updated last year
- ☆37Updated last year
- Kernel driver for detecting Intel VT-x hypervisors.☆192Updated 2 years ago
- Exploit vulnerabilities in NeacSafe64.sys to achieve privilege escalation and kernel-mode shellcode execution☆65Updated 6 months ago