stormshield / HiveSwarmingLinks
Convert .reg to registry hive and reciprocally, without elevation
☆21Updated 2 months ago
Alternatives and similar repositories for HiveSwarming
Users that are interested in HiveSwarming are comparing it to the libraries listed below
Sorting:
- Example/starter code for custom Windows application compatibility shims☆33Updated 4 years ago
- An example of how to use Microsoft Windows Warbird technology☆28Updated 2 years ago
- A fast method to intercept syscalls from any user-mode process using InstrumentationCallback and detect any process using Instrumentation…☆31Updated last year
- A hooking library with a MinHook-like API and a Detours-like implementation, with support for the x86, x64, and ARM64 platforms☆21Updated last week
- A fully compatible replacement of Windows NT NtCreateLowBoxToken syscall - precisely restored from reverse engineering☆38Updated 2 weeks ago
- Listing UDP connections with remote address without sniffing.☆29Updated last year
- ☆40Updated 4 months ago
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆78Updated last week
- ☆16Updated 2 years ago
- WinREPL is a "read-eval-print loop" shell on Windows that is useful for testing/learning x86 and x64 assembly.☆17Updated 2 years ago
- ☆31Updated last year
- SetWinEventHook Sample☆48Updated last year
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆34Updated 3 years ago
- Remote Thread Detection with a Kernel Driver☆30Updated 5 months ago
- Dump certificates from PE files in different formats☆38Updated last year
- WinXPSP2.Cermalus on stereoids, supporting all 32 bits Windows version. Windows Kernel Virus stuff for noobs☆18Updated last year
- A few examples of how to trap virtual memory access on Windows.☆31Updated 6 months ago
- PoC for the Untrusted Pointer Dereference in the appid.sys driver☆16Updated last year
- The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent …☆39Updated 2 years ago
- Enabled / Disable LSA Protection via BYOVD☆70Updated 3 years ago
- https://github.com/janoglezcampos/c_syscalls with the ASM rewritten by myself for Visual Studio's Compiler.☆31Updated last year
- An x64dbg plugin which marks XFG call signatures as data☆77Updated 2 years ago
- UAC via computerdefaults.exe☆12Updated 2 months ago
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆30Updated 10 months ago
- Command line utility for copying files on NTFS using low level disk access☆35Updated last year
- Process Injection: APC Injection☆33Updated 4 years ago
- ☆11Updated 3 years ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆34Updated 3 years ago
- ☆25Updated 2 years ago
- Example of building an application verifer DLL☆46Updated last year