socjordi / sauron
Windows Monitoring Agent (process creation + DLL loading monitor + network monitor + file system access monitor + etc)
☆59Updated 5 years ago
Related projects: ⓘ
- windows rpc 使用MIDL+RPC实现HelloWorld☆20Updated 6 years ago
- ☆27Updated 3 years ago
- Trace events in real time sessions☆42Updated last year
- A driver to intercept low level windows events☆59Updated 4 years ago
- ☆32Updated 3 years ago
- Easy Transparent Encrypted File System Based on Minifilter File System Driver☆33Updated 11 months ago
- PoC executable packer using resources☆31Updated 7 years ago
- it can extract functions from .dll, .exe, .sys and it be work! :)☆38Updated 5 years ago
- Win32 API and COM hooking/tracing.☆31Updated 8 years ago
- A simple ransomware defender.It uses minifilter to filt "rewrite" and "delete" events in kernel.And it handles event in user mode.☆26Updated 6 years ago
- ☆13Updated this week
- ☆38Updated last year
- View handles and object for each object type☆61Updated 5 years ago
- c++ implementation of windows heavens gate☆54Updated 3 years ago
- Library for ETW, ProcessTracker sample based on ETW☆33Updated 7 years ago
- ☆18Updated 6 years ago
- a network filter using NDIS hook technique☆18Updated 11 years ago
- 大表哥的Syscall-Monitor☆33Updated 5 years ago
- Lightweight Portable Executable parsing library and a demo peParser application.☆71Updated last year
- A File System Filter Driver for file I/O monitors, file access control, transparent file encryption.☆30Updated last year
- HTTP/HTTPS/DNS inspector (windows driver)☆23Updated 5 years ago
- 粗暴地枚举管理内核的WFP对象。 Manage kernel WFPs in a brutal way.☆26Updated 6 years ago
- Windows Simple Process Logger implemented as driver☆18Updated 6 years ago
- Open Source Libraries Collection☆24Updated 8 years ago
- Simple command line version of Sysinternals WinObj. Currently just lists object names and types given an object manager directory.☆19Updated last year
- Windows Minifilter driver that redirects any I/O Request of mp3 files to a target file☆15Updated 9 years ago
- ☆12Updated 5 years ago
- For Example. See Miro's Blog☆29Updated last year
- Call 32bit NtDLL API directly from WoW64 Layer☆59Updated 3 years ago
- Detects if a Kernel mode debugger is active by reading the value of KUSER_SHARED_DATA.KdDebuggerEnabled. It is a high level and portable …☆22Updated 7 years ago