Hooking kernel functions by abusing alignment
☆248Jan 5, 2021Updated 5 years ago
Alternatives and similar repositories for owned_alignment
Users that are interested in owned_alignment are comparing it to the libraries listed below
Sorting:
- C++ graphics kernel subsystem hook☆562Jan 11, 2021Updated 5 years ago
- Intercepting DeviceControl via WPP☆138Nov 18, 2019Updated 6 years ago
- Hide codes/data in the kernel address space.☆188May 8, 2021Updated 4 years ago
- Rendering on external windows via hijacking thread contexts☆404Jun 28, 2020Updated 5 years ago
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.☆345Apr 27, 2020Updated 5 years ago
- Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.☆905Nov 21, 2019Updated 6 years ago
- PoC EFI runtime driver for memory r/w & kdmapper fork☆571Nov 30, 2024Updated last year
- Access without a real handle☆1,041Apr 10, 2021Updated 4 years ago
- This program remaps its image to prevent the page protection of pages contained in the image from being modified via NtProtectVirtualMemo…☆632Mar 19, 2019Updated 7 years ago
- ☆185May 5, 2019Updated 6 years ago
- Manual mapping without creating any threads, with rw only access☆808Oct 29, 2019Updated 6 years ago
- DLL scatter manual mapper☆813Apr 10, 2021Updated 4 years ago
- BattlEye compatible injector, done completely from user-mode, project by secret.club☆251Oct 25, 2020Updated 5 years ago
- EasyAntiCheat Integrity check bypass by mimicking memory changes☆353Sep 13, 2020Updated 5 years ago
- C++ Exceptions in Windows Drivers☆222Dec 21, 2020Updated 5 years ago
- Kernel mode bypass for BattlEye, EAC☆189Oct 25, 2023Updated 2 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆107May 10, 2022Updated 3 years ago
- Communication via callback☆73Oct 9, 2019Updated 6 years ago
- Kernel-mode Windows HWID spoofer☆612Jan 22, 2024Updated 2 years ago
- Module extending manual mapper☆382Mar 28, 2020Updated 5 years ago
- The functions interception library written on pure C and NativeAPI with UserMode and KernelMode support☆764Apr 24, 2025Updated 10 months ago
- Kernel driver that uses Shared memory to communicate with UserMode☆86Apr 25, 2019Updated 6 years ago
- Windows driver for spoofing serial number of HDDs☆220Sep 8, 2022Updated 3 years ago
- a more stable & secure read/write virtual memory for kernel mode drivers☆161Mar 8, 2020Updated 6 years ago
- Discarded Section Manual Map☆70Jun 18, 2020Updated 5 years ago
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆220Nov 12, 2020Updated 5 years ago
- Reversing EasyAntiCheat.☆586Apr 19, 2019Updated 6 years ago
- the basic version of the ring0 physical memory read/write tool☆92Aug 18, 2019Updated 6 years ago
- win10 pgContext dynamic dump (btc version)☆110Jan 15, 2020Updated 6 years ago
- Proof of concept on how to bypass some limitations of a manual mapped driver☆172Oct 24, 2020Updated 5 years ago
- SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.☆468Feb 18, 2021Updated 5 years ago
- Prototype of hijacking Windows driver dispatch routines in unmapped discardable sections☆55Mar 30, 2019Updated 6 years ago
- System call hook for Windows 10 20H1☆496Jun 26, 2021Updated 4 years ago
- Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking☆492Dec 12, 2018Updated 7 years ago
- C++17 PE manualmapper☆441Oct 2, 2021Updated 4 years ago
- ☆75Dec 17, 2019Updated 6 years ago
- UEFI bootkit for driver manual mapping☆589Jan 1, 2024Updated 2 years ago
- driver manual mapper (outdated/for educational purposes)☆115May 17, 2019Updated 6 years ago
- Hook system calls on Windows by using Kaspersky's hypervisor☆1,285Feb 14, 2026Updated last month