stonedreamforest / NaiHeQiao
open-source x86/x64 usermode anti-anti-debug plugin
☆215Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for NaiHeQiao
- Hide Driver By MiProcessLoaderEntry☆281Updated 5 years ago
- pseudo-code to show how to disable patchguard with win10☆295Updated 6 years ago
- kernel-mode Anti-Anti-Debug plugin. based on intel vt-x && ept technology☆429Updated 4 years ago
- VMProtect 3.x Anti-debug Method Improved☆522Updated 5 years ago
- FuckXC3☆89Updated 6 years ago
- LLVM Obfuscator / constexpr / PEB CALL API☆172Updated 5 years ago
- Windows Ark 工具的工程和一些demo☆185Updated 8 years ago
- Windows kernel mode driver to prevent detection of debuggers.☆95Updated 9 years ago
- Some ways to inject a DLL into a alive process☆353Updated 6 years ago
- Page fault hook use ept (Intel Virtualization Technology)☆175Updated 8 years ago
- An Ark tool project,run on Win7 x86/x64☆110Updated 7 years ago
- modify from memorymodule. support exception☆211Updated 4 years ago
- PatchGuard Research☆292Updated 6 years ago
- Exploiting CPU-Z Driver To Turn Load Unsigned Drivers☆125Updated 7 years ago
- Kernel Anit Anit Debug Plugins 内核反反调试插件☆449Updated 3 years ago
- Open-source user-mode Anti-Anti-Debug plugin for x64dbg & cheatengine.☆192Updated 7 years ago
- 同时支持用户和内核模式的Inlinehook库☆120Updated 6 years ago
- Syscall Monitor is a system monitor program (like Sysinternal's Process Monitor) using Intel VT-X/EPT for Windows7+☆722Updated 7 years ago
- VMProtect OD Plugin☆91Updated 8 years ago
- ☆116Updated 6 years ago
- Add More Features for x64dbg Script System,with some Functions which will help Plugin Coder☆123Updated 2 years ago
- StrongOD(anti anti-debug plugin) driver source code.☆113Updated 7 years ago
- A VMP to VTIL lifter.☆424Updated 3 years ago
- win32下的虚拟机保护壳☆136Updated 9 years ago
- Unicorn PE is an unicorn based instrumentation project designed to emulate code execution for windows PE files.☆787Updated 6 months ago
- ☆466Updated 8 years ago
- Hide codes/data in the kernel address space.☆185Updated 3 years ago
- A dynamic VMP dumper and import fixer, powered by VTIL.☆41Updated 4 years ago
- An Attempt to Bypass Memory Scanners By Misusing the ntdll.dll "RT" Section.☆95Updated 8 years ago
- kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x☆413Updated 2 years ago