Hades HIDS/HIPS for Windows
☆312May 23, 2026Updated 3 months ago
Alternatives and similar repositories for Hades-Windows
Users that are interested in Hades-Windows are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Hades is a Host-Based Intrusion Detection System based on both eBPF(kernel) and netlink/cn_proc(userspace).☆28May 28, 2026Updated 3 months ago
- Windows CVE主防(HIPS/HIDS)☆58May 2, 2026Updated 4 months ago
- VT Hook☆60May 3, 2026Updated 3 months ago
- Windows Anti-Rootkit Tool☆572Jul 25, 2026Updated last month
- ☆178Sep 9, 2020Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- It's a minifilter used for transparent-encrypting.☆349Jul 28, 2025Updated last year
- VM一键加壳/脱壳,全压缩,反调试等☆375Apr 30, 2026Updated 4 months ago
- Radical Windows ARK☆256Apr 18, 2025Updated last year
- ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detecti…☆323Mar 20, 2024Updated 2 years ago
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆307May 24, 2026Updated 3 months ago
- Analyze Windows x64 Kernel Memory Layout☆134Nov 19, 2020Updated 5 years ago
- The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层…☆379Feb 19, 2025Updated last year
- 戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑☆532Oct 25, 2023Updated 2 years ago
- ☆317May 11, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- windows kernel pagehook☆43Oct 30, 2022Updated 3 years ago
- Windows一键检测应急响应服务工具/r3数据采集☆100Apr 5, 2022Updated 4 years ago
- 40行代码检测到大部分CobaltStrike的shellcode☆292Jul 25, 2021Updated 5 years ago
- 从MmPfnData中枚举进程和页目录基址☆225Aug 18, 2023Updated 3 years ago
- 粗暴地枚举管理内核的WFP对象。 Manage kernel WFPs in a brutal way.☆24Jan 14, 2018Updated 8 years ago
- Hook system calls on Windows by using Kaspersky's hypervisor☆1,316Apr 2, 2026Updated 5 months ago
- https://key08.com/index.php/2021/10/19/1375.html☆70May 11, 2022Updated 4 years ago
- a monitoring windows driver calls kernel api tools☆139Jul 5, 2024Updated 2 years ago
- Using NtCreateFile and NtDeviceIoControlFile to realize the function of winsock(利用NtCreateFile和NtDeviceIoControlFile 实现winsock的功能)☆130Sep 9, 2022Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x☆458Nov 29, 2021Updated 4 years ago
- 检测绝大部分所谓的内存免杀马☆732Sep 15, 2022Updated 3 years ago
- iDefender - The Infinite Potential Host Intrusion Prevention System (HIPS) & Real-time Endpoint Detection and Response for Home☆314Aug 9, 2026Updated 3 weeks ago
- Call NtCreateUserProcess directly as normal.☆77May 17, 2022Updated 4 years ago
- Open-source EDR kernel-component for system monitoring and DLL injection☆33Nov 14, 2020Updated 5 years ago
- WFP驱动,关联链路层和进程信息☆16Oct 17, 2021Updated 4 years ago
- Security product hook detection☆326Mar 30, 2021Updated 5 years ago
- libcodecs is part of the "Huorong eXtendible Stream Scan Engine" project copyright by Huorong Borui (Beijing) Technology Co., Ltd.☆24Aug 17, 2015Updated 11 years ago
- iMonitor(冰镜 - 终端行为分析系统)☆833Feb 1, 2026Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThrea…☆1,328Jun 21, 2024Updated 2 years ago
- 无痕注入1☆74Jun 1, 2021Updated 5 years ago
- Reverse engineered source code of the autochk rootkit☆214Nov 1, 2019Updated 6 years ago
- 内核驱动加载/卸载痕迹清理,努力绕过反作弊吧 PiDDBCacheTable and MmLastUnloadedDriver☆191Feb 11, 2023Updated 3 years ago
- 让Etwhook再次伟大! Make InfinityHook Great Again!☆148Jun 24, 2021Updated 5 years ago
- 隐藏可执行内存☆276Apr 27, 2025Updated last year
- For Example. See Miro's Blog☆29Nov 26, 2022Updated 3 years ago