woldann / NHookLinks
Minimal inline hooking for Windows x64 without trampoline — 2-byte infinite loop hook, cross-process support via NThread.
☆18Updated last week
Alternatives and similar repositories for NHook
Users that are interested in NHook are comparing it to the libraries listed below
Sorting:
- x86-64 user mode emulation using Zydis☆47Updated 5 months ago
- llvm powered deobfuscation of a vm-based protection☆36Updated 2 months ago
- This is the PoC of a dynamic lifter and deobfuscator with collecting trace.☆34Updated last year
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆66Updated last year
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆34Updated 3 years ago
- Easy-to-use IDA plugin for code emulation☆33Updated last year
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated 2 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆16Updated 3 years ago
- api-tracer is a tiny (useless) tracer☆14Updated 2 years ago
- IDA plugin to deobfuscate emotet CFF☆18Updated 3 years ago
- Simplifier vmp ultra☆18Updated last year
- Repository of different kernel drivers written while studying Windows NT Driver development☆12Updated last year
- A Windows API hooking library !☆31Updated 2 years ago
- A driver to implement IOCTL hooking☆24Updated 3 years ago
- This is a ring -1 header framework in order to simplify the creation of hypervisors on SVM☆24Updated last year
- IDA Type Info Libraries for RE☆31Updated 5 months ago
- ☆18Updated 4 months ago
- A Binary Ninja plugin to deobfuscate Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆31Updated 10 months ago
- Binary Ninja plugin for automating VMProtect analysis☆61Updated 2 years ago
- Windows kernel driver template for cmkr and llvm-msvc.☆35Updated last year
- IDA plugin to quickly learn what a shortcut does☆10Updated 3 years ago
- ☆15Updated 2 years ago
- ☆21Updated 4 months ago
- A Windows executable (PE) packer (x64) with LZMA compression and with full TLS (Thread Local Storage) support☆57Updated last week
- Generate a PDB file given the old PDB file and an address mapping☆48Updated 3 months ago
- Header-only C++ library for producing PE files.☆33Updated 2 years ago
- ☆13Updated 4 months ago
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆36Updated 9 months ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆82Updated 10 months ago
- ANY.RUN sandbox detection collection☆19Updated 10 months ago