vovkos / protolesshooks
API monitoring via return-hijacking thunks; works without information about target function prototypes.
☆112Updated 4 years ago
Related projects: ⓘ
- This project aims to facilitate debugging a kernel driver in windows by adding support for a code change on the fly without reboot/unload…☆167Updated last year
- A modern c++ implementation of windows heavens gate☆193Updated 4 years ago
- C++ Exceptions in Windows Drivers☆195Updated 3 years ago
- Global user-mode hooking framework, based on AppInit_DLLs. The goal is to allow you to rapidly develop hooks to inject in an arbitrary pr…☆156Updated 2 years ago
- ☆119Updated 3 weeks ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆129Updated 5 years ago
- usermode standalone kernel interface☆110Updated 6 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆129Updated 4 years ago
- x86-64 virtual machine and disassembler☆125Updated 4 years ago
- COFF and Portable Executable format described using standard C++ with no dependencies.☆251Updated 5 months ago
- Header only wrapper around Hex-Rays API in C++20.☆147Updated 2 years ago
- API Set resolver for Windows☆114Updated last week
- A driver that hooks C: volume using symbolic link callback to track all FS access to the volume☆100Updated 4 years ago
- Translates WinDbg "dt" structure dump to a C structure☆126Updated 7 years ago
- A Windows kernel dump C++ parser library with Python 3 bindings.☆193Updated 2 months ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆203Updated 4 years ago
- x64 usermode rootkit☆199Updated 6 years ago
- Three Tiny Examples of Directly Using Vista's NtCreateUserProcess☆84Updated 8 years ago
- Cross-platform tool that allows browsing and extracting C and C++ type declarations from PDB files.☆281Updated 3 weeks ago
- Resolve DOS MZ executable symbols at runtime☆93Updated 2 years ago
- ☆28Updated 5 years ago
- Basic Windows Kernel Programming☆120Updated 4 years ago
- Research on Windows Kernel Executive Callback Objects☆277Updated 4 years ago
- ☆105Updated 5 years ago
- Analyze patches in a process☆241Updated 3 years ago
- APC Internals Research Code☆155Updated 4 years ago
- ☆137Updated this week
- A native hypervisor designed for the Windows operating system☆120Updated 3 years ago
- An example of a client and server using Windows' ALPC functions to send and receive data.☆88Updated 4 years ago
- A Windows PE format file loader☆137Updated 6 years ago