Rookit and anti rookit on Windows platform
☆14Apr 30, 2024Updated last year
Alternatives and similar repositories for Rootkit
Users that are interested in Rootkit are comparing it to the libraries listed below
Sorting:
- Inject dll to process in driver☆10Aug 27, 2024Updated last year
- Kernel mode to user mode dll injection.☆14Nov 10, 2024Updated last year
- Demo to show how write ALPC Client & Server using native Ntdll.dll syscalls.☆21Jan 25, 2022Updated 4 years ago
- Bypassing kernel patch protection runtime☆22Feb 19, 2023Updated 3 years ago
- PsSetCreateProcessNotifyRoutine/Ex/Ex2 hook☆12May 30, 2024Updated last year
- DllInject (Memory Load)☆11Jan 5, 2019Updated 7 years ago
- Header only c++ network library, based on asio,support tcp,udp,http,websocket,rpc,ssl,icmp,serial_port.☆10Nov 20, 2020Updated 5 years ago
- High-level library for executable binary file analysis☆16Feb 13, 2017Updated 9 years ago
- Windows Kernel Mode PCRE☆10Feb 4, 2015Updated 11 years ago
- 编译时混淆字符串,以确保生成的二进制PE不会暴漏明文字符串。(C++ 14 及以上)☆29Sep 30, 2021Updated 4 years ago
- 内存加载DLL 支持VMP最大加密☆12Aug 11, 2020Updated 5 years ago
- ☆18Feb 6, 2019Updated 7 years ago
- 废物自救项目!一起向光而行!!!☆11May 7, 2022Updated 3 years ago
- IDA plugin: fold decomplied code☆11Nov 26, 2021Updated 4 years ago
- Windows安全防火墙☆14Aug 25, 2020Updated 5 years ago
- Enumerates very, very large directories quickly by directly using kernel syscalls. For POSIX and Windows. WARNING THIS IS OBSOLETE. USE B…☆15Aug 13, 2014Updated 11 years ago
- Kernel Context [template c++] Library - K C L. Your stl for work in linux/windows kernel !!!☆11Jul 24, 2018Updated 7 years ago
- x86、x64通用,远程注入DLL并得到HMODULE。☆13May 22, 2019Updated 6 years ago
- some classes which can help me to program kernel driver in Windows.☆16Feb 9, 2018Updated 8 years ago
- Modify data structures in the Windows kernel, hiding processes by PID☆16Oct 29, 2017Updated 8 years ago
- [POC Detected]Bypass BE Anti Dll Injection (POC/Need Driver)☆17Mar 30, 2020Updated 5 years ago
- What makes it page☆17Aug 24, 2022Updated 3 years ago
- Modern x64 anti-debug library☆10Oct 29, 2019Updated 6 years ago
- Convert native dll to shellcode, and support exported function☆25Feb 10, 2021Updated 5 years ago
- LPC (Local Procedure Call) is a portion of Windows NT kernel, used for fast communication between threads or processes. It can be also us…☆15Mar 21, 2021Updated 4 years ago
- Very tiny and selective implementation of STL for Windows NT kernel mode drivers☆18Jun 22, 2021Updated 4 years ago
- 简易远程桌面控制☆14Aug 22, 2020Updated 5 years ago
- Minifilter Driver☆15Feb 10, 2017Updated 9 years ago
- Bring Your Own Vulnerable Driver for PatchGuard & Driver Signature Enforcement☆14Apr 6, 2024Updated last year
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆62Jan 29, 2026Updated last month
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆84Dec 21, 2022Updated 3 years ago
- Single-header LZW (Lempel-Ziv-Welch) C Library, headerless compressor & decompressor (variable code, 9-16 bits)☆22Jan 2, 2026Updated last month
- Kernel Inject Process☆11Jul 28, 2017Updated 8 years ago
- eac memory sig maker☆14Jun 10, 2021Updated 4 years ago
- Windows注入内核感染导入表注入X64☆13Oct 20, 2018Updated 7 years ago
- 卓然主动防御源码(可执行文件+完整源码+完整作品报告)☆15Mar 5, 2019Updated 6 years ago
- Anti-Rootkit & System kernel management tool☆51Jan 24, 2026Updated last month
- A set of Windows 10+/VS2022/C++14 tools for working with software modifications in two files (Detours.h, Detours.cpp).☆46Feb 1, 2026Updated 3 weeks ago
- Inject remote shellcode or DLL file into process memory using FileMapping☆15Aug 6, 2023Updated 2 years ago