vmcall / owned_alignment
Hooking kernel functions by abusing alignment
☆238Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for owned_alignment
- Memory hacking library powered by AMD SVM☆297Updated last year
- Module extending manual mapper☆309Updated 4 years ago
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.☆251Updated 4 years ago
- a more stable & secure read/write virtual memory for kernel mode drivers☆160Updated 4 years ago
- C++17 PE manualmapper☆259Updated 3 years ago
- driver mapper / capcom wrapper☆215Updated 5 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆302Updated 2 years ago
- Proof of concept on how to bypass some limitations of a manual mapped driver☆164Updated 4 years ago
- An Injector that can inject dll into game process protected by anti cheat using SetWindowsHookEx.☆239Updated 5 years ago
- Rendering on external windows via hijacking thread contexts☆378Updated 4 years ago
- A customizable process dumper.☆129Updated 5 years ago
- ☆139Updated 3 years ago
- Intercepting DeviceControl via WPP☆127Updated 5 years ago
- ☆160Updated 7 years ago
- Windows kernel samples☆247Updated 5 years ago
- Stealthy UM <-> KM communication system without creating any system threads, permanent hooks, driver objects, section objects or device o…☆360Updated 8 months ago
- ☆153Updated 5 years ago
- Vectored Exception Handling Hooking Class☆145Updated 5 years ago
- A library to read physical memory and system-wide virtual memory.☆122Updated 6 years ago
- 09/2021 reversal of EasyAntiCheat driver☆204Updated 2 years ago
- ☆182Updated 5 years ago
- BattlEye compatible injector, done completely from user-mode, project by secret.club☆237Updated 4 years ago
- A library to manipulate physical memory from usermode.☆292Updated last year
- Manual mapper that uses PTE manipulation, Virtual Address Descriptor (VAD) manipulation, and forceful memory allocation to hide executabl…☆289Updated 2 years ago
- Kernel cheat with kernel hook for communication☆295Updated 3 years ago
- Driver that uses network sockets to communicate with client and read/ write protected process memory.☆449Updated 5 years ago
- manually map driver for a signed driver memory space☆138Updated 3 years ago
- Kernel mode bypass for BattlEye, EAC☆186Updated last year
- A mapper that maps shellcode into loaded large page drivers☆229Updated 2 years ago