一个windows内核驱动分析框架,对内核所有导出函数进行挂钩监控
☆69Nov 19, 2025Updated 3 months ago
Alternatives and similar repositories for kernel_monitor
Users that are interested in kernel_monitor are comparing it to the libraries listed below
Sorting:
- 一个用来做windows内核hook的框架☆188Apr 29, 2025Updated 10 months ago
- 使用 Intel 虚拟化特性实现应用层HOOK☆65Sep 11, 2025Updated 5 months ago
- windows rpc 使用MIDL+RPC实现HelloWorld☆23Mar 21, 2018Updated 7 years ago
- The Universal C++ RunTime library, supporting kernel-mode C++ exception-handler and STL.☆131Aug 26, 2025Updated 6 months ago
- 一个仅使用2字节修改实现内核任意函数hook的方法。☆58May 17, 2025Updated 9 months ago
- https://www.huorong.cn/☆15Apr 16, 2024Updated last year
- an encryption library designed for Windows kernel and driver programming☆123Aug 4, 2023Updated 2 years ago
- Kernel-Mode extended version of https://github.com/microsoft/Detours☆180Jun 1, 2025Updated 8 months ago
- Radical Windows ARK☆251Apr 18, 2025Updated 10 months ago
- Inject dll to process in driver☆10Aug 27, 2024Updated last year
- 从MmPfnData中枚举进程和页目录基址☆205Aug 18, 2023Updated 2 years ago
- Monitor ETW events for Windows process mitigation policies, with stack traces☆31Oct 7, 2022Updated 3 years ago
- UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.☆44Jan 21, 2023Updated 3 years ago
- a monitoring windows driver calls kernel api tools☆126Jul 5, 2024Updated last year
- etw hook (syscall/infinity hook) compatible with the latest Windows version of PG☆324Apr 27, 2024Updated last year
- Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.☆96Aug 26, 2025Updated 6 months ago
- Very tiny and selective implementation of STL for Windows NT kernel mode drivers☆18Jun 22, 2021Updated 4 years ago
- ☆47Feb 3, 2025Updated last year
- ☆223Mar 11, 2023Updated 2 years ago
- A SOCKS5-configured syscall hook that allows transparent TCP proxying on Windows for IPv4 and IPv6.☆26Jul 9, 2021Updated 4 years ago
- A very simple C++ library for download pdb, get rva of function, global variable and offset from struct.☆158Mar 26, 2024Updated last year
- 卓然主动防御源码(可执行文件+完整源码+完整作品报告)☆15Mar 5, 2019Updated 6 years ago
- 内核驱动加载/卸载痕迹清理,努力绕过反作弊吧 PiDDBCacheTable and MmLastUnloadedDriver☆189Feb 11, 2023Updated 3 years ago
- Anti-Rootkit & System kernel management tool☆51Jan 24, 2026Updated last month
- first commit☆64Oct 29, 2020Updated 5 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆107May 10, 2022Updated 3 years ago
- ☆56Nov 21, 2022Updated 3 years ago
- Static user/kernel mode library that allows access to all functions and global variables by extracting offsets from the PDB☆118May 29, 2025Updated 8 months ago
- Small class to parse debug info from PEs, download their respective PDBs from the Microsoft Public Symbol Server and calculate RVAs of fu…☆44Apr 1, 2023Updated 2 years ago
- Windows Minifilter driver that redirects any I/O Request of mp3 files to a target file☆18Jul 7, 2015Updated 10 years ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆34Feb 7, 2022Updated 4 years ago
- InfinityHookPro Win7 -> Win11 latest☆551Feb 7, 2023Updated 3 years ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆176Sep 13, 2024Updated last year
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆219Nov 12, 2020Updated 5 years ago
- An improved Detours.☆107Updated this week
- ☆129Sep 24, 2023Updated 2 years ago
- Kernel dwm render☆168Oct 10, 2023Updated 2 years ago
- It's a kernel-based keylogger for Windows x86/x64.☆145Sep 18, 2022Updated 3 years ago
- Windows Kernel Security: Memory Integrity Verification with Disk Verification of ntoskrnl.exe☆15Mar 23, 2025Updated 11 months ago