一个windows内核驱动分析框架,对内核所有导出函数进行挂钩监控
☆69Nov 19, 2025Updated 4 months ago
Alternatives and similar repositories for kernel_monitor
Users that are interested in kernel_monitor are comparing it to the libraries listed below
Sorting:
- 一个用来做windows内核hook的框架☆188Apr 29, 2025Updated 10 months ago
- 使用 Intel 虚拟化特性实现应用层HOOK☆66Sep 11, 2025Updated 6 months ago
- The Universal C++ RunTime library, supporting kernel-mode C++ exception-handler and STL.☆131Aug 26, 2025Updated 6 months ago
- 一个仅使用2字节修改实现内核任意函数hook的方法。☆58May 17, 2025Updated 10 months ago
- windows rpc 使用MIDL+RPC实现HelloWorld☆23Mar 21, 2018Updated 7 years ago
- https://www.huorong.cn/☆15Apr 16, 2024Updated last year
- Kernel-Mode extended version of https://github.com/microsoft/Detours☆180Jun 1, 2025Updated 9 months ago
- Radical Windows ARK☆252Apr 18, 2025Updated 11 months ago
- Inject dll to process in driver☆10Aug 27, 2024Updated last year
- 从MmPfnData中枚举进程和页目录基址☆208Aug 18, 2023Updated 2 years ago
- etw hook (syscall/infinity hook) compatible with the latest Windows version of PG☆328Apr 27, 2024Updated last year
- ☆225Mar 11, 2023Updated 3 years ago
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Jan 21, 2023Updated 3 years ago
- an encryption library designed for Windows kernel and driver programming☆124Aug 4, 2023Updated 2 years ago
- ☆45Sep 25, 2024Updated last year
- Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.☆96Aug 26, 2025Updated 6 months ago
- a monitoring windows driver calls kernel api tools☆129Jul 5, 2024Updated last year
- Hook NtDeviceIoControlFile with PatchGuard☆107May 10, 2022Updated 3 years ago
- Monitor ETW events for Windows process mitigation policies, with stack traces☆31Oct 7, 2022Updated 3 years ago
- InfinityHookPro Win7 -> Win11 latest☆553Feb 7, 2023Updated 3 years ago
- 内核驱动加载/卸载痕迹清理,努力绕过反作弊吧 PiDDBCacheTable and MmLastUnloadedDriver☆189Feb 11, 2023Updated 3 years ago
- A very simple C++ library for download pdb, get rva of function, global variable and offset from struct.☆159Mar 26, 2024Updated last year
- Kernel Context [template c++] Library - K C L. Your stl for work in linux/windows kernel !!!☆11Jul 24, 2018Updated 7 years ago
- 针对windows rootkit的一些检测,分别从进程、端口、文件这三个方面进行检测。☆21Jan 16, 2025Updated last year
- first commit☆64Oct 29, 2020Updated 5 years ago
- A .data pointer hook with communication in windows 11☆46Nov 9, 2025Updated 4 months ago
- Static user/kernel mode library that allows access to all functions and global variables by extracting offsets from the PDB☆118May 29, 2025Updated 9 months ago
- ☆56Nov 21, 2022Updated 3 years ago
- Kernel dwm render☆170Oct 10, 2023Updated 2 years ago
- Windows Minifilter driver that redirects any I/O Request of mp3 files to a target file☆18Jul 7, 2015Updated 10 years ago
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆220Nov 12, 2020Updated 5 years ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆121Feb 8, 2022Updated 4 years ago
- ☆47Feb 3, 2025Updated last year
- ☆132Sep 24, 2023Updated 2 years ago
- ☆10Dec 28, 2023Updated 2 years ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆177Sep 13, 2024Updated last year
- ☆309May 11, 2023Updated 2 years ago
- Anti-Rootkit & System kernel management tool☆55Jan 24, 2026Updated last month
- 可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。☆109Sep 1, 2022Updated 3 years ago