rogxo / ReadPhys
r/w virtual memory without attach
☆158Updated last year
Alternatives and similar repositories for ReadPhys:
Users that are interested in ReadPhys are comparing it to the libraries listed below
- ☆177Updated last year
- ☆146Updated 2 years ago
- ☆160Updated 2 years ago
- 从MmPfnData中枚举进程和页目录基址☆153Updated last year
- Kernel dwm render☆136Updated last year
- Standard Kernel Library for Windows hacking in C++☆118Updated last month
- ☆196Updated last year
- ☆119Updated last year
- Unknowncheats Magically Optimized Tidy Mapper using nvaudio☆113Updated 7 months ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆144Updated 4 months ago
- Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver☆162Updated last year
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆207Updated 4 years ago
- This project migrated to https://github.com/backengineering/llvm-msvc☆141Updated last year
- Use RTCore64 to map your driver on windows 11.☆95Updated 9 months ago
- Example of reading process memory through kernel special APC☆100Updated last year
- ShotHv☆130Updated 2 years ago
- query-pdb is a server-side software for parsing PDB files. The software provides PDB online parsing service.☆148Updated 4 months ago
- A very simple C++ library for download pdb, get rva of function, global variable and offset from struct.☆114Updated 9 months ago
- Windows Kernel inject (no module no thread)☆269Updated 2 years ago
- ☆134Updated 11 months ago
- Forked LLVM focused on MSVC Compatibility. This version is designed for windows users☆82Updated last week
- ☆127Updated 2 years ago
- etw hook (syscall/infinity hook) compatible with the latest Windows version of PG☆226Updated 8 months ago
- manual map unsigned driver over signed memory☆184Updated 9 months ago
- InfinityHook 支持Win7 到 Win11 最新版本,虚拟机环境及物理机 环境☆43Updated 3 months ago
- Loads a signed kernel driver which allows you to map any driver to kernel mode without any traces of the signed / mapped driver.☆298Updated 3 years ago
- DWM Overlay without modify .text☆59Updated 4 months ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆109Updated 2 years ago
- A mapper that maps shellcode into loaded large page drivers☆244Updated 2 years ago
- ☆177Updated 3 years ago