skadro-official / PE-Dump-Fixer
PE-Dump-Fixer
☆105Updated 5 years ago
Alternatives and similar repositories for PE-Dump-Fixer
Users that are interested in PE-Dump-Fixer are comparing it to the libraries listed below
Sorting:
- Attempts to decrypt JM Xorstr in some x64 binaries☆55Updated 2 years ago
- Hygieia, a vulnerable driver traces scanner written in C++ as an x64 Windows kernel driver.☆143Updated 3 years ago
- Ghetto user mode emulation of Windows kernel drivers.☆137Updated 6 months ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆112Updated 3 years ago
- A PoC for requesting HWIDs directly from hardware, skipping any potential hooks or OS support.☆80Updated 4 years ago
- A devirtualization engine for Themida.☆100Updated last year
- A simple ida python script to find .data ptr☆51Updated 2 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆184Updated last year
- Kernel driver that uses Shared memory to communicate with UserMode☆85Updated 6 years ago
- 🪝 Different aproaches to detecting EPT hooks☆108Updated 3 years ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆59Updated last year
- Some usefull info when reverse engineering Kernel Mode Anti-Cheat☆71Updated 2 years ago
- ☆74Updated last year
- just proof of concept. hooking MmCopyMemory PG safe.☆70Updated last year
- Kernel ReClassEx☆62Updated last year
- reverse engineering of bedaisy.sys (battleyes kernel driver) - Aki2k/BEDaisy☆83Updated 4 years ago
- Kernel Lazy Importer☆113Updated last year
- Discarded Section Manual Map☆67Updated 4 years ago
- Bypassing EasyAntiCheat.sys self-integrity by abusing call hierarchy☆81Updated 2 years ago
- Handling C++ & __try exceptions without the need of built-in handlers.☆71Updated 3 years ago
- based on https://github.com/secrary/Hooking-via-InstrumentationCallback☆71Updated 5 years ago
- Various IDA scripts I've created for Reverse engineering.☆85Updated 6 months ago
- ☆122Updated 2 years ago
- x64 Windows kernel driver mapper, inject unsigned driver using anycall☆157Updated last year
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆44Updated last year
- A simple tool to assemble shellcode ready to be copy-pasted into code☆69Updated 2 years ago
- Windows PDB parser for kernel-mode environment.☆96Updated 2 years ago
- Some psuedo snippets from BattlEye's BEDaisy.sys loaded on Rainbow Six: Siege.☆124Updated 3 years ago
- A basic demonstration of directly overwriting paging structures for physical memory r/w and interprocess memory copy☆86Updated last year
- Based on physmeme☆69Updated 3 years ago