Illustrates the concept of return address spoofing, and how it is used.
☆14May 13, 2020Updated 6 years ago
Alternatives and similar repositories for Return-address-spoofer
Users that are interested in Return-address-spoofer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Hijack NotifyRoutine for a kernelmode thread☆38Jun 4, 2022Updated 4 years ago
- A minimalistic way to spoof return addresses without using exceptions☆21Jul 26, 2022Updated 4 years ago
- UM-KM Communication using registry callbacks☆39Jun 8, 2020Updated 6 years ago
- ☆46Oct 19, 2021Updated 4 years ago
- ☆118Aug 7, 2022Updated 4 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Some drivers I've written while solving exercises from Practical Reverse Engineering☆15Jan 9, 2022Updated 4 years ago
- ☆37May 21, 2022Updated 4 years ago
- Old way for blocking NMI interrupts☆29Sep 6, 2022Updated 4 years ago
- Fixes the "Device\Nal is already in use" error on kdmapper.☆20Jan 9, 2023Updated 3 years ago
- base for testing☆198Sep 28, 2024Updated last year
- An example code of CiGetCertPublisherName☆15Mar 24, 2022Updated 4 years ago
- A PoC for requesting HWIDs directly from hardware, skipping any potential hooks or OS support.☆90Mar 16, 2021Updated 5 years ago
- A lightweight x86/x64 VM☆18Feb 7, 2021Updated 5 years ago
- Windows kernel drivers simple HTTP library for modern C++☆41Jul 12, 2018Updated 8 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆165Nov 14, 2021Updated 4 years ago
- clearing traces of a loaded driver☆48Jul 2, 2022Updated 4 years ago
- An x64 page table iterator written in C++ as a kernel mode windows driver.☆123May 25, 2021Updated 5 years ago
- search for a driver/dll module that has a wanted section bigger than the size of your image☆21Aug 14, 2021Updated 5 years ago
- ☆59Jun 8, 2022Updated 4 years ago
- A simple tool to assemble shellcode ready to be copy-pasted into code☆71Jun 13, 2022Updated 4 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆18Jan 15, 2022Updated 4 years ago
- PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and pre…☆58May 23, 2022Updated 4 years ago
- Using CVE-2021-40449 to manual map kernel mode driver☆104Mar 5, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Medal.tv Hook / D3D Present & ResizeBuffers Hook☆21Oct 3, 2022Updated 3 years ago
- ☆42Apr 18, 2023Updated 3 years ago
- Feature-rich C99 library for memory scanning purposes, designed for Windows running machines, meant to work on both 32-bit and 64-bit por…☆31Feb 7, 2026Updated 6 months ago
- CVE-2022-3699 with arbitrary kernel code execution capability☆72Dec 27, 2022Updated 3 years ago
- Experimental disassembler for x86 binaries virtualized by VMProtect 3☆97Aug 27, 2022Updated 4 years ago
- ☆39Mar 23, 2023Updated 3 years ago
- Using SetWindowHookEx for preinjected DLL's☆58Aug 25, 2022Updated 4 years ago
- Programmatically set hardware breakpoint with C++ on Windows☆39Feb 21, 2024Updated 2 years ago
- Easy to include string and wstring obfuscation☆25Mar 12, 2022Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Walks the Process' VAD list to grab the PTE's corresponding to a usermode virtual address, all to get the physical address☆23Nov 22, 2021Updated 4 years ago
- Basic utilities for executing, reading and writing 64-bit data in a 32-bit WoW64 process☆20Jul 8, 2022Updated 4 years ago
- vdk is a set of utilities used to help with exploitation of a vulnerable driver.☆48May 22, 2022Updated 4 years ago
- Compileable POC of namazso's x64 return address spoofer.☆51Jun 10, 2020Updated 6 years ago
- PsSetCreateProcessNotifyRoutine/Ex/Ex2 hook☆13May 30, 2024Updated 2 years ago
- ☆142Jan 13, 2021Updated 5 years ago
- ☆27May 17, 2022Updated 4 years ago