tandasat / FU_Hypervisor
A hypervisor hiding user-mode memory using EPT
☆106Updated 7 years ago
Alternatives and similar repositories for FU_Hypervisor:
Users that are interested in FU_Hypervisor are comparing it to the libraries listed below
- ☆123Updated 4 years ago
- Collect different versions of Crucial modules.☆129Updated 7 months ago
- ☆94Updated 7 years ago
- hook msr by amd svm☆119Updated 5 years ago
- ayy debuger☆88Updated 11 months ago
- first commit☆57Updated 4 years ago
- the basic version of the ring0 physical memory read/write tool☆89Updated 5 years ago
- Windows Driver Kit Extesion Header (Undoc)☆132Updated 3 years ago
- Hide codes/data in the kernel address space.☆188Updated 3 years ago
- An Ark tool project,run on Win7 x86/x64☆113Updated 7 years ago
- Intercepting DeviceControl via WPP☆130Updated 5 years ago
- ☆110Updated 5 years ago
- Simple Intel VT-x hypervisor☆278Updated last year
- Page fault hook use ept (Intel Virtualization Technology)☆181Updated 8 years ago
- x64 free protect Features 1.process/thread handle protect 2.anti taskmgr.exe 3.hide process 4.anti-debugger(user/kernel debugger)☆81Updated 5 years ago
- An x64 page table iterator written in C++ as a kernel mode windows driver.☆107Updated 3 years ago
- Windows Kernel Template Library☆108Updated 2 years ago
- Hooking SSDT with Avast Internet Security Hypervisor☆113Updated 5 years ago
- Static user/kernel mode library that allows access to all functions and global variables by extracting offsets from the PDB☆80Updated last year
- ☆64Updated 11 years ago
- Шаблон полнофункционального драйвера и обёртки над ядерным API☆111Updated 8 years ago
- ☆153Updated 5 years ago
- 让Etwhook再次伟大! Make InfinityHook Great Again!☆128Updated 3 years ago
- Intel Virtualization Technology demo☆65Updated 8 years ago
- Different aproaches to detecting EPT hooks☆89Updated 2 years ago
- Communication via callback☆73Updated 5 years ago
- win10 pgContext dynamic dump (btc version)☆104Updated 5 years ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆150Updated 5 months ago
- 之前那份是7600的,每次编译搞得好麻烦。更新一个VS2017可以直接编译的。☆147Updated 5 years ago
- Windows Manipulation Library (x64, User/Kernelmode)☆75Updated 6 years ago