pvthuyet / windows-kernel-programmingLinks
Windows kernel
☆12Updated 5 years ago
Alternatives and similar repositories for windows-kernel-programming
Users that are interested in windows-kernel-programming are comparing it to the libraries listed below
Sorting:
- A Practical example of ELAM (Early Launch Anti-Malware)☆35Updated 3 years ago
- the Open Source and Pure C++ Packer for eXecutables☆21Updated 2 years ago
- This script is used to unload PsSetCreateProcessNotifyRoutineEx, PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine and PsSetCr…☆62Updated last year
- Repository of Microsoft Driver Block Lists based off of OS-builds☆40Updated last year
- ☆30Updated 2 months ago
- NT AUTHORITY\SYSTEM☆42Updated 5 years ago
- Listing UDP connections with remote address without sniffing.☆29Updated 2 years ago
- ☆19Updated 4 years ago
- Process Ghosting is a technique in which a process is created from a delete pending file. This means the created process is not backed by…☆16Updated last year
- Piece of code to detect and remove hooks in IAT☆64Updated 3 years ago
- Manually perform syscalls without going through any external API or DLL.☆19Updated 2 years ago
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆35Updated last year
- Infects PE files with a shellcode☆20Updated 7 years ago
- BYOVD Technique Example using viragt64 driver☆57Updated last year
- Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver☆52Updated 2 years ago
- Hooking Heavens Gate in a weekend☆13Updated 3 years ago
- API Hammering with C++20☆49Updated 3 years ago
- Windows kernel driver encryption library, support base64, aes-256, rsa-2048 and higher, ecc-256, single file, minimal dependence, support…☆22Updated 4 years ago
- Signature finder (from PE-bear)☆38Updated 2 months ago
- Callstack spoofing using a VEH because VEH all the things.☆23Updated 7 months ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆26Updated 2 years ago
- ☆33Updated last year
- Parser for a custom executable formats from Hidden Bee and Rhadamanthys malware☆56Updated 2 months ago
- Process Injection: APC Injection☆32Updated 4 years ago
- Your NTDLL vaccine from modern direct syscall methods.☆36Updated 3 years ago
- SetWinEventHook Sample☆49Updated 2 years ago
- ☆26Updated 3 years ago
- A repository filled with ideas to break/detect direct syscall techniques☆27Updated 3 years ago
- Simple API Hooks detector☆75Updated 3 years ago
- A Bumblebee-inspired Crypter☆78Updated 2 years ago