☆82Aug 17, 2021Updated 4 years ago
Alternatives and similar repositories for SystemThreadFinder
Users that are interested in SystemThreadFinder are comparing it to the libraries listed below
Sorting:
- ☆84Apr 1, 2022Updated 3 years ago
- This project will give you an example how you can hook a kernel vtable function that cannot be directly called☆84Dec 25, 2021Updated 4 years ago
- ☆17Dec 3, 2020Updated 5 years ago
- Detect removed thread from PspCidTable.☆75Mar 18, 2022Updated 3 years ago
- ☆50Dec 19, 2023Updated 2 years ago
- ☆192Dec 8, 2021Updated 4 years ago
- ☆29Dec 29, 2022Updated 3 years ago
- ☆48Mar 29, 2022Updated 3 years ago
- A kernelmode driver swapping a .data pointer in the kernel to perform communication between the kernel and usermode.☆142Oct 20, 2020Updated 5 years ago
- ☆13Aug 4, 2022Updated 3 years ago
- ☆18Feb 5, 2025Updated last year
- Hijack NotifyRoutine for a kernelmode thread☆41Jun 4, 2022Updated 3 years ago
- As i was busy reversing the githubs^^ i stumbled on old source which allows you to control driver kernal^^ with IOCTL, amazing rite?☆23Jul 15, 2021Updated 4 years ago
- x64 assembler library☆31Jun 7, 2024Updated last year
- Code for Battleyes shellcode☆239Nov 11, 2021Updated 4 years ago
- mouseclassservicecallback detection via hook☆52Feb 7, 2022Updated 4 years ago
- Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode☆163Jul 31, 2022Updated 3 years ago
- Discarded Section Manual Map☆70Jun 18, 2020Updated 5 years ago
- Hiding the window from screenshots using the function win32kfull::GreProtectSpriteContent☆628Dec 26, 2024Updated last year
- base for testing☆186Sep 28, 2024Updated last year
- BattlEye shellcodes tester☆151Jan 3, 2022Updated 4 years ago
- A mapper that maps shellcode into loaded large page drivers☆324Apr 26, 2022Updated 3 years ago
- comparing data of module exports from disk and memory, then caching any differences.☆26Dec 11, 2021Updated 4 years ago
- ☆27Oct 16, 2017Updated 8 years ago
- Loads a signed kernel driver which allows you to map any driver to kernel mode without any traces of the signed / mapped driver.☆382Aug 8, 2021Updated 4 years ago
- Using SetWindowHookEx for preinjected DLL's☆57Aug 25, 2022Updated 3 years ago
- Bypasses for Windows kernel callbacks PatchGuard protection☆44Aug 15, 2021Updated 4 years ago
- Two PoC of accessing process virtual memory via NT Kernel☆22Jun 25, 2021Updated 4 years ago
- ☆14May 10, 2021Updated 4 years ago
- nmi stackwalking + module verification☆162Dec 28, 2023Updated 2 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆107May 10, 2022Updated 3 years ago
- scan system / process integrity☆350Oct 22, 2024Updated last year
- 09/2021 reversal of EasyAntiCheat driver☆235Dec 21, 2021Updated 4 years ago
- Some crazy PE executables protection kernel driver☆20May 2, 2020Updated 5 years ago
- UM-KM Communication using registry callbacks☆39Jun 8, 2020Updated 5 years ago
- Known ring3 memory protections that can be handled at a simple level.☆67Jan 28, 2023Updated 3 years ago
- POC usermode <=> kernel communication via ALPC.☆72Jun 6, 2024Updated last year
- Mapping your code on a 0x1000 size page☆71May 20, 2022Updated 3 years ago
- Plugin for ReClass.Net (using vulnerable driver to read process memory)☆94Jan 2, 2020Updated 6 years ago