rbmm / remap
break link between dll and it file on disk
☆11Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for remap
- Example of building an application verifer DLL☆45Updated 5 months ago
- Easy encrypt/decrypt data with TPM☆24Updated 8 months ago
- ☆27Updated 4 months ago
- Native Powers Talk demos☆14Updated last year
- An example of how to use Microsoft Windows Warbird technology☆25Updated last year
- In-memory hiding technique☆43Updated 5 months ago
- Repository of Microsoft Driver Block Lists based off of OS-builds☆38Updated 6 months ago
- ☆27Updated 2 years ago
- ☆16Updated 2 years ago
- Enabled / Disable LSA Protection via BYOVD☆62Updated 2 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆28Updated 2 years ago
- research revolving the windows filtering platform callout mechanism☆20Updated 5 months ago
- ☆8Updated this week
- ☆84Updated 5 months ago
- ☆13Updated last year
- Demo from the Malware Analysis and Development Webinar☆19Updated 6 months ago
- Six cases demonstrating methods of optimizing GetProcAddress☆17Updated 2 years ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆30Updated last year
- ☆12Updated last year
- Rust bindings to the System Informer's (formerly known as Process Hacker) "phnt" native Windows headers☆38Updated last month
- ☆27Updated 11 months ago
- Set the process mitigation policy for loading only Microsoft Modules , and block any userland 3rd party modules☆42Updated last year
- Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle…☆15Updated last year
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆30Updated last month
- Finding Truth in the Shadows☆84Updated last year
- Enumerate Callbacks and all Object Types☆13Updated last year
- A native Windows library for intercepting kernel-to-user transitions using instrumentation callbacks☆16Updated 9 months ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆24Updated last year
- Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping☆45Updated 2 years ago
- silence file system monitoring components by hooking their minifilters☆51Updated 9 months ago