A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.
☆119Feb 1, 2022Updated 4 years ago
Alternatives and similar repositories for manual-syscall-detect
Users that are interested in manual-syscall-detect are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ETW based POC to identify direct and indirect syscalls☆195Apr 19, 2023Updated 3 years ago
- A way to detect DBI frameworks, Debuggers and VMs.☆25Nov 17, 2020Updated 5 years ago
- Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll☆516Feb 3, 2022Updated 4 years ago
- Security product hook detection☆326Mar 30, 2021Updated 5 years ago
- PoC capable of detecting manual syscalls from usermode.☆211Nov 13, 2025Updated 9 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Code Injection, Inject malicious payload via pagetables pml4.☆244Jul 7, 2021Updated 5 years ago
- RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, …☆499Jan 25, 2022Updated 4 years ago
- ☆70Feb 6, 2025Updated last year
- A simple program to hook the current process to identify the manual syscall executions on windows☆266Nov 18, 2022Updated 3 years ago
- FreshyCalls tries to make the use of syscalls comfortable and simple, without generating too much boilerplate and in modern C++17!☆363Sep 1, 2022Updated 3 years ago
- A copy of my Mathematics and Computer Engineering B.Sc. thesis☆18Dec 8, 2020Updated 5 years ago
- Analyze patches in a process☆264Jul 28, 2021Updated 5 years ago
- ☆27Dec 29, 2021Updated 4 years ago
- Inline syscalls made easy for windows on clang☆741Jun 21, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Lightweight WINAPI tracing with Pin☆26Aug 22, 2019Updated 7 years ago
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆420Jul 6, 2022Updated 4 years ago
- DoppelGate relies on reading ntdll on disk to grab syscall stubs, and patches these syscall stubs into desired functions to bypass Userla…☆124Mar 25, 2022Updated 4 years ago
- SyscallLoader☆11Sep 13, 2021Updated 4 years ago
- ☆42Apr 22, 2021Updated 5 years ago
- Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique☆337Jan 16, 2022Updated 4 years ago
- devirtualization vmprotect☆70Mar 11, 2023Updated 3 years ago
- A kernel mode Windows rootkit in development.☆47Dec 31, 2021Updated 4 years ago
- Proof-of-Concept software for detecting AV/EDR hooks in Windows libraries.☆38May 12, 2022Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Load and execute COFF files and Cobalt Strike BOFs in-memory☆228Sep 13, 2022Updated 3 years ago
- Recon 2015 Presentation from Alex Ionescu☆253Jan 27, 2016Updated 10 years ago
- WTSRM☆214Aug 7, 2022Updated 4 years ago
- Hookers are cooler than patches.☆171Jan 21, 2022Updated 4 years ago
- The Definitive Guide To Process Cloning on Windows☆556Jan 3, 2024Updated 2 years ago
- x64 Kernel Hooks Detection☆21Jan 1, 2017Updated 9 years ago
- Load any Beacon Object File using Powershell!☆261Dec 9, 2021Updated 4 years ago
- Universal x86/x64 VMProtect 2.0-3.X Import fixer☆34Dec 29, 2021Updated 4 years ago
- A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC☆376May 24, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- LoadLibrary for offensive operations☆1,190Oct 22, 2021Updated 4 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆164Nov 14, 2021Updated 4 years ago
- Monitor ETW events for Windows process mitigation policies, with stack traces☆30Oct 7, 2022Updated 3 years ago
- PoC: Exploit 32-bit Thread Snapshot of WOW64 to Take Over $RIP & Inject & Bypass Antivirus HIPS (HITB 2021)☆163May 27, 2021Updated 5 years ago
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆300Apr 10, 2021Updated 5 years ago
- An example code of CiGetCertPublisherName☆15Mar 24, 2022Updated 4 years ago
- A simple x86_64 AMD-v hypervisor type-2 Programmed with C++, with soon to be added syscall hooks. [W.I.P]☆113Aug 3, 2023Updated 3 years ago