Illustrates the concept of return address spoofing, and how it is used.
☆14May 13, 2020Updated 6 years ago
Alternatives and similar repositories for Return-address-spoofer
Users that are interested in Return-address-spoofer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Hijack NotifyRoutine for a kernelmode thread☆38Jun 4, 2022Updated 4 years ago
- A minimalistic way to spoof return addresses without using exceptions☆21Jul 26, 2022Updated 4 years ago
- UM-KM Communication using registry callbacks☆39Jun 8, 2020Updated 6 years ago
- ☆45Oct 19, 2021Updated 4 years ago
- ☆118Aug 7, 2022Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Some drivers I've written while solving exercises from Practical Reverse Engineering☆15Jan 9, 2022Updated 4 years ago
- ☆37May 21, 2022Updated 4 years ago
- Old way for blocking NMI interrupts☆28Sep 6, 2022Updated 3 years ago
- Fixes the "Device\Nal is already in use" error on kdmapper.☆20Jan 9, 2023Updated 3 years ago
- base for testing☆193Sep 28, 2024Updated last year
- An example code of CiGetCertPublisherName☆15Mar 24, 2022Updated 4 years ago
- A PoC for requesting HWIDs directly from hardware, skipping any potential hooks or OS support.☆88Mar 16, 2021Updated 5 years ago
- A lightweight x86/x64 VM☆18Feb 7, 2021Updated 5 years ago
- Windows kernel drivers simple HTTP library for modern C++☆40Jul 12, 2018Updated 8 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆160Nov 14, 2021Updated 4 years ago
- clearing traces of a loaded driver☆48Jul 2, 2022Updated 4 years ago
- An x64 page table iterator written in C++ as a kernel mode windows driver.☆122May 25, 2021Updated 5 years ago
- search for a driver/dll module that has a wanted section bigger than the size of your image☆21Aug 14, 2021Updated 4 years ago
- ☆59Jun 8, 2022Updated 4 years ago
- A simple tool to assemble shellcode ready to be copy-pasted into code☆70Jun 13, 2022Updated 4 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆18Jan 15, 2022Updated 4 years ago
- Using CVE-2021-40449 to manual map kernel mode driver☆103Mar 5, 2022Updated 4 years ago
- PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and pre…☆58May 23, 2022Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Medal.tv Hook / D3D Present & ResizeBuffers Hook☆21Oct 3, 2022Updated 3 years ago
- ☆43Apr 18, 2023Updated 3 years ago
- Feature-rich C99 library for memory scanning purposes, designed for Windows running machines, meant to work on both 32-bit and 64-bit por…☆31Feb 7, 2026Updated 5 months ago
- CVE-2022-3699 with arbitrary kernel code execution capability☆72Dec 27, 2022Updated 3 years ago
- Experimental disassembler for x86 binaries virtualized by VMProtect 3☆97Aug 27, 2022Updated 3 years ago
- ☆40Mar 23, 2023Updated 3 years ago
- Using SetWindowHookEx for preinjected DLL's☆58Aug 25, 2022Updated 3 years ago
- Programmatically set hardware breakpoint with C++ on Windows☆38Feb 21, 2024Updated 2 years ago
- Easy to include string and wstring obfuscation☆25Mar 12, 2022Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆23Nov 22, 2021Updated 4 years ago
- Basic utilities for executing, reading and writing 64-bit data in a 32-bit WoW64 process☆20Jul 8, 2022Updated 4 years ago
- vdk is a set of utilities used to help with exploitation of a vulnerable driver.☆48May 22, 2022Updated 4 years ago
- Compileable POC of namazso's x64 return address spoofer.☆51Jun 10, 2020Updated 6 years ago
- PsSetCreateProcessNotifyRoutine/Ex/Ex2 hook☆13May 30, 2024Updated 2 years ago
- ☆143Jan 13, 2021Updated 5 years ago
- ☆26May 17, 2022Updated 4 years ago