tandasat / findpgView external linksLinks
Windbg extension to find PatchGuard pages
☆123Jun 24, 2014Updated 11 years ago
Alternatives and similar repositories for findpg
Users that are interested in findpg are comparing it to the libraries listed below
Sorting:
- PatchGuard Research☆304Oct 6, 2018Updated 7 years ago
- Demo List cm/ps/ob/minifilter callback And Patch/Bypass it☆29Dec 5, 2017Updated 8 years ago
- User-mode program parsing logs created by HyperPlatform☆18Aug 15, 2016Updated 9 years ago
- ☆12Feb 19, 2017Updated 8 years ago
- Hypervisor based tool for monitoring system register accesses.☆153Sep 13, 2018Updated 7 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Aug 12, 2015Updated 10 years ago
- Elevation of privilege detector based on HyperPlatform☆124Mar 5, 2017Updated 8 years ago
- Windows Kernel Driver - Create a driver device in TDI layer of windows kernel to capture network data packets☆36Jul 21, 2014Updated 11 years ago
- more at http://www.zer0mem.sk/?p=271☆12Jun 11, 2013Updated 12 years ago
- 内核级ARK工具。☆62Aug 1, 2016Updated 9 years ago
- Detecting execution of kernel memory where is not backed by any image file☆262Jul 11, 2018Updated 7 years ago
- nyā☆70Oct 16, 2015Updated 10 years ago
- ☆14Aug 15, 2018Updated 7 years ago
- Analysing and defeating PatchGuard universally☆36Nov 4, 2020Updated 5 years ago
- pseudo-code to show how to disable patchguard with win10☆294Jan 13, 2018Updated 8 years ago
- A windbg extension, extracting token related contents☆41Dec 23, 2020Updated 5 years ago
- use crystalCPUID to identify vt-x & amd-v☆17Apr 8, 2015Updated 10 years ago
- An aggregate of tools used in the core of vmp_dbg plus other parsing utils to parse vmp bc.☆16Oct 18, 2016Updated 9 years ago
- Windows kernel-mode callbacks tutorial driver☆48Aug 8, 2016Updated 9 years ago
- Modify process handle permissions☆61Nov 30, 2016Updated 9 years ago
- ☆36Oct 29, 2020Updated 5 years ago
- Automatically exported from code.google.com/p/guardlite☆11Jul 2, 2015Updated 10 years ago
- Wow64 syscall hook☆42May 28, 2017Updated 8 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆27May 21, 2014Updated 11 years ago
- Debugger extension for the Debugging Tools for Windows (WinDbg, KD, CDB, NTSD).☆69Nov 14, 2016Updated 9 years ago
- A command line tool to load and unload a device driver.☆46Jun 10, 2017Updated 8 years ago
- Hook IDT vector 0xb2 to detect SCI in 64bit windows.☆34Aug 27, 2022Updated 3 years ago
- Automatically exported from code.google.com/p/virtdbg☆99Jun 25, 2015Updated 10 years ago
- kernel pool windbg extension☆83Jul 23, 2015Updated 10 years ago
- An Ark tool project,run on Win7 x86/x64☆118Jul 11, 2017Updated 8 years ago
- ☆15Jun 12, 2015Updated 10 years ago
- A system call tracer☆10Sep 22, 2014Updated 11 years ago
- Windows driver including couple different techniques for file removal when regular operation isn't possible.☆70Feb 11, 2016Updated 10 years ago
- windows kernel File redirection☆20Sep 21, 2014Updated 11 years ago
- ☆14Jan 10, 2017Updated 9 years ago
- Exploiting CPU-Z Driver To Turn Load Unsigned Drivers☆131Aug 10, 2017Updated 8 years ago
- AllMemPro☆46Jan 15, 2018Updated 8 years ago
- A hypervisor hiding user-mode memory using EPT☆107Jan 28, 2018Updated 8 years ago
- IDA反-反调试插件 IDAStealth v1.3.3, created 06/28/2011, Jan Newger☆21Apr 4, 2018Updated 7 years ago