pvthuyet / windows-kernel-programming
Windows kernel
☆12Updated 4 years ago
Alternatives and similar repositories for windows-kernel-programming:
Users that are interested in windows-kernel-programming are comparing it to the libraries listed below
- ☆12Updated this week
- Windows kernel driver encryption library, support base64, aes-256, rsa-2048 and higher, ecc-256, single file, minimal dependence, support…☆21Updated 3 years ago
- ☆27Updated 6 months ago
- ☆29Updated last year
- ☆26Updated 3 months ago
- Offensive Assembly code snippets.☆12Updated last year
- ☆11Updated 2 weeks ago
- ☆12Updated last year
- A simple PE loader.☆25Updated 2 years ago
- Research into removing strings & API call references at compile-time (Anti-Analysis)☆24Updated 7 months ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆54Updated 2 years ago
- Evilbytecode-Gate resolves Windows System Service Numbers (SSNs) using two methods: analyzing the Guard CF Table in ntdll.dll and parsing…☆15Updated last week
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- Implementation of ITaskHandler in C++☆13Updated last year
- API Hammering with C++20☆43Updated 2 years ago
- Repository of Microsoft Driver Block Lists based off of OS-builds☆39Updated 9 months ago
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆26Updated 5 months ago
- Process Injection: APC Injection☆29Updated 4 years ago
- Manually perform syscalls without going through any external API or DLL.☆17Updated last year
- This script is used to unload PsSetCreateProcessNotifyRoutineEx, PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine and PsSetCr…☆62Updated 11 months ago
- ☆27Updated 2 years ago
- Antivirus killer using ring-0 kernel driver. Antivirus processes will automatically close while the killer is running.☆6Updated 2 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆33Updated 3 years ago
- using the Recycle Bin to insure persistence☆12Updated 2 years ago
- A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.☆38Updated 4 years ago
- Six cases demonstrating methods of optimizing GetProcAddress☆17Updated 3 years ago
- 2022 Updated Kernelmode-Code☆31Updated 9 months ago
- A repository filled with ideas to break/detect direct syscall techniques☆26Updated 2 years ago