stormshield / Beholder-Win32Links
A sample on how to inject a DLL from a kernel driver
☆62Updated 8 years ago
Alternatives and similar repositories for Beholder-Win32
Users that are interested in Beholder-Win32 are comparing it to the libraries listed below
Sorting:
- Code injection by hijacking threads in Windows 32-bit applications☆43Updated 6 years ago
- (DEPRECATED) A simple anti-anti debug library for Windows☆29Updated 5 years ago
- Manual PE image mapper☆65Updated 12 years ago
- Windows handle stealing POC with NtDuplicateObject☆40Updated 8 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆79Updated 14 years ago
- A reflexive driver loader to bypass Windows DSE (featuring a custom PE loader)☆42Updated 6 years ago
- Analysing and defeating PatchGuard universally☆35Updated 4 years ago
- driver interface with dll-injection capabilities☆29Updated 4 years ago
- Remote memory library in C++17.☆31Updated 7 years ago
- Small tool which loads Windows drivers with NtLoadDriver☆44Updated 4 years ago
- Standalone program to download PDB Symbol files for debugging without WDK☆79Updated 6 years ago
- usermode standalone kernel interface☆111Updated 7 years ago
- A simple kernel mode driver that hooks some values at the KUSER_SHARED_DATA structure.☆26Updated 5 years ago
- win32/x64 obfuscate framework☆32Updated 6 years ago
- A simple program to scan for open handles in a process.☆61Updated 8 years ago
- ☆24Updated 6 years ago
- Driver Loader/BE Bypass/Win Malware(lol)☆34Updated 6 years ago
- kernel-mode TDI client which can send and receive HTTP requests☆55Updated 7 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆57Updated 6 years ago
- Example of hijacking system calls via function pointer tables☆31Updated 4 years ago
- Polymorphic Stub Creator☆34Updated 8 years ago
- Simple code generation library developed in C intended for code generation in Kernel mode☆17Updated 2 years ago
- Stealthy Injector that leverages a vulnerable driver and other exploits to remain undetected☆36Updated 6 years ago
- Driver demonstrating how to register a DPC to asynchronously wait on an object☆49Updated 4 years ago
- New handle stealing technique for windows apps☆13Updated 7 years ago
- Figuring out the cause of a handle downgrade☆24Updated 2 years ago
- Capcom wrapper with safety in mind.☆82Updated 7 years ago
- Hiding x32/x64 Modules/DLLs using PEB☆61Updated 10 years ago
- LoadLibrary, GetModuleHandle and GetProcAddress calls for remote processes☆22Updated 10 years ago
- This is the first software system, which can detect a stealthy hypervisor and calculate several nested ones even under countermeasures.☆84Updated 10 years ago