trailofbits / HVCI-loldrivers-check
☆52Updated last year
Alternatives and similar repositories for HVCI-loldrivers-check:
Users that are interested in HVCI-loldrivers-check are comparing it to the libraries listed below
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated last month
- Winbindex bot to pull in binaries for specific releases☆47Updated last year
- ☆18Updated last year
- A Poc on blocking Procmon from monitoring network events☆100Updated 2 years ago
- Contains all the applications developed for the Second part of the 7th Edition of Windows Internals book☆108Updated 9 months ago
- ☆110Updated 2 years ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- ☆23Updated last year
- a tiny program to consume from ETW providers for research☆46Updated 2 months ago
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆37Updated last year
- ☆73Updated 8 months ago
- A few examples of how to trap virtual memory access on Windows.☆28Updated 3 months ago
- Recon 2023 slides and code☆79Updated last year
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆106Updated 6 months ago
- C# Utilities for Windows Notification Facility☆131Updated 4 months ago
- List the ETW provider(s) in the registration table of a process.☆57Updated last year
- ☆29Updated last month
- Slides for COM Hijacking AV/EDR Talk on 38c3☆73Updated 2 months ago
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆98Updated last year
- A more reliable way of resolving syscall numbers in Windows☆48Updated last year
- ☆51Updated 5 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆96Updated 11 months ago
- Finding Truth in the Shadows☆89Updated 2 years ago
- ☆71Updated 7 months ago
- Select any exported function in a dll as the new dll's entry point.☆75Updated 5 months ago
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆73Updated last year
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆47Updated this week
- ☆155Updated 10 months ago
- Piece of code to detect and remove hooks in IAT☆63Updated 2 years ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆26Updated last year