pikulet / anti-debugging
demo of common anti-analysis techniques used by malware
☆16Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for anti-debugging
- Simple windows API logger☆98Updated 5 years ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆32Updated last year
- A research project about Windows notify routines.☆35Updated 4 years ago
- An automatic tool for fixing dumped PE files☆41Updated 4 years ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- Python 3 - Manipulation and conversation with different data type (Bytes operations)☆27Updated 2 years ago
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago
- VinCSS Reverse Engineering, Malware Analysing Tools & Ultilities☆26Updated 2 years ago
- Anti-Debug encyclopedia contains methods used by malware to verify if they are executed under debugging. It includes the description of v…☆49Updated last year
- Neutralize KEPServerEX anti-debugging techniques☆31Updated last year
- allowing um r/w through km from um ioctl ™☆12Updated 2 years ago
- This is a simple driver with x64 inline assembly☆52Updated 4 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆73Updated 13 years ago
- api-tracer is a tiny (useless) tracer☆13Updated last year
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆69Updated last year
- Yet another Windows DLL injector.☆38Updated 2 years ago
- Miscellaneous Code and Docs☆77Updated 11 months ago
- Implementation of Advanced Module Stomping and Heap/Stack Encryption☆9Updated last year
- A collection of tools, source code, and papers researching Windows' implementation of CET.☆74Updated 4 years ago
- Abusing exceptions for code execution.☆106Updated last year
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆36Updated 2 years ago
- A driver to implement IOCTL hooking☆23Updated 2 years ago
- ☆22Updated 4 years ago
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆84Updated 2 years ago
- Resolve DOS MZ executable symbols at runtime☆93Updated 3 years ago
- 2022 Updated Kernelmode-Code☆30Updated 7 months ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆57Updated 2 months ago
- Simple x64dbg plugin to save a full memory dump☆49Updated 2 years ago
- PyKD DLLs for x86 and x64 platforms☆14Updated last year