smallzhong / kernel_monitor
一个windows内核驱动分析框架,对内核所有导出函数进行挂钩监控
☆31Updated last week
Alternatives and similar repositories for kernel_monitor:
Users that are interested in kernel_monitor are comparing it to the libraries listed below
- ☆52Updated 2 years ago
- Enum and Remove Hook in Windows☆38Updated 4 months ago
- Hook NtDeviceIoControlFile with PatchGuard☆105Updated 2 years ago
- 利用物理内存映射,实现虚拟内存的伪隐藏☆83Updated 2 years ago
- ☆16Updated 6 months ago
- ☆27Updated last year
- 收集常用windows版本内核文件☆32Updated last year
- 不使用3环挂钩进行DWM桌面绘制☆80Updated 3 years ago
- ☆35Updated 7 months ago
- VT Hook☆46Updated 10 months ago
- 使用 Intel 虚拟化特性实现应用层HOOK☆60Updated 2 months ago
- ☆80Updated 3 years ago
- ☆43Updated 8 months ago
- SymbolTypeViewer_汉化☆16Updated 4 years ago
- Windows kernel drivers simple HTTP library for modern C++☆42Updated 6 years ago
- ☆68Updated 3 years ago
- Visual Studio 2019/2022 extension for building C/C++ projects with the LLVM Compiler Toolchain (installed separately).☆18Updated 6 months ago
- This project can bypass most of the AC except for some perverts that enable VT to monitor page tables☆41Updated 11 months ago
- sc4cpp is a shellcode framework based on C++☆88Updated 3 years ago
- 自写驱动内存注入☆27Updated 3 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆29Updated 4 months ago
- Win7内核私有符号结构转储☆67Updated 3 years ago
- Quick check of NT kernel exported&unexported functions/global variable offset NT内核导出以及未导出函数+全局变量偏移速查☆93Updated 2 years ago
- Forked LLVM focused on MSVC Compatibility. This version is designed for windows users☆94Updated last month
- ☆42Updated 3 months ago
- 一个用来做windows内核hook的框架☆116Updated last week
- ☆132Updated 2 years ago
- bootkit驱动映射,三环进程注入加载指定模块☆13Updated 6 months ago
- ☆48Updated 2 years ago
- InfinityHook 支持Win7 到 Win11 最新版本,虚拟机环境及物理机环境☆56Updated 6 months ago