Rookit and anti rookit on Windows platform
☆14Apr 30, 2024Updated last year
Alternatives and similar repositories for Rootkit
Users that are interested in Rootkit are comparing it to the libraries listed below
Sorting:
- Inject dll to process in driver☆10Aug 27, 2024Updated last year
- PsSetCreateProcessNotifyRoutine/Ex/Ex2 hook☆13May 30, 2024Updated last year
- High-level library for executable binary file analysis☆16Feb 13, 2017Updated 9 years ago
- Demo to show how write ALPC Client & Server using native Ntdll.dll syscalls.☆21Jan 25, 2022Updated 4 years ago
- ☆18Feb 6, 2019Updated 7 years ago
- Windows Kernel Mode PCRE☆10Feb 4, 2015Updated 11 years ago
- Reverse Engineering☆13Jun 22, 2017Updated 8 years ago
- Kernel Context [template c++] Library - K C L. Your stl for work in linux/windows kernel !!!☆11Jul 24, 2018Updated 7 years ago
- Header only c++ network library, based on asio,support tcp,udp,http,websocket,rpc,ssl,icmp,serial_port.☆10Nov 20, 2020Updated 5 years ago
- Bypassing kernel patch protection runtime☆22Feb 19, 2023Updated 3 years ago
- Simple tool to dump/hide services in services.exe process.☆14Apr 22, 2022Updated 3 years ago
- Convert native dll to shellcode, and support exported function☆25Feb 10, 2021Updated 5 years ago
- some classes which can help me to program kernel driver in Windows.☆16Feb 9, 2018Updated 8 years ago
- 废物自救项目!一起向光而行!!!☆11May 7, 2022Updated 3 years ago
- 编译时混淆字符串,以确保生成的二进制PE不会暴漏明文字符串。(C++ 14 及以上)☆30Sep 30, 2021Updated 4 years ago
- defender_database☆24Oct 31, 2023Updated 2 years ago
- .lib file for linking against the NT CRT☆19Mar 18, 2022Updated 4 years ago
- Single-header LZW (Lempel-Ziv-Welch) C Library, headerless compressor & decompressor (variable code, 9-16 bits)☆22Jan 2, 2026Updated 2 months ago
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆62Jan 29, 2026Updated last month
- Enumerates very, very large directories quickly by directly using kernel syscalls. For POSIX and Windows. WARNING THIS IS OBSOLETE. USE B…☆15Aug 13, 2014Updated 11 years ago
- IDA plugin: fold decomplied code☆11Nov 26, 2021Updated 4 years ago
- Minifilter Driver☆15Feb 10, 2017Updated 9 years ago
- An attempt at reversing WindowsDefender☆20Oct 6, 2024Updated last year
- ☆19Oct 25, 2024Updated last year
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆83Dec 21, 2022Updated 3 years ago
- Hide Port In Windows☆42Oct 24, 2024Updated last year
- ☆17Mar 3, 2016Updated 10 years ago
- 非编译时代码混淆,包括代码块拆分、代码乱序、常量加密、代码变异、抹除jcc、局部混淆等,主要提供框架以及思路☆33Mar 12, 2023Updated 3 years ago
- LPC (Local Procedure Call) is a portion of Windows NT kernel, used for fast communication between threads or processes. It can be also us…☆15Mar 21, 2021Updated 5 years ago
- windows kernel pagehook☆42Oct 30, 2022Updated 3 years ago
- Helper functions for calculating the authenticode digest for a portable executable file☆21Apr 30, 2020Updated 5 years ago
- ☆18Aug 15, 2025Updated 7 months ago
- ☆16May 22, 2014Updated 11 years ago
- Collection of self-made Red Team tools that have come in handy☆12Aug 25, 2024Updated last year
- ☆14May 10, 2021Updated 4 years ago
- windows inlinehook R3 R0☆11Apr 11, 2018Updated 7 years ago
- ☆15Dec 16, 2020Updated 5 years ago
- Anti-Rootkit & System kernel management tool☆55Jan 24, 2026Updated last month
- DllInject (Memory Load)☆11Jan 5, 2019Updated 7 years ago