A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.
☆118Feb 1, 2022Updated 4 years ago
Alternatives and similar repositories for manual-syscall-detect
Users that are interested in manual-syscall-detect are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ETW based POC to identify direct and indirect syscalls☆196Apr 19, 2023Updated 3 years ago
- A way to detect DBI frameworks, Debuggers and VMs.☆24Nov 17, 2020Updated 5 years ago
- Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll☆511Feb 3, 2022Updated 4 years ago
- Security product hook detection☆326Mar 30, 2021Updated 5 years ago
- PoC capable of detecting manual syscalls from usermode.☆210Nov 13, 2025Updated 8 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Code Injection, Inject malicious payload via pagetables pml4.☆245Jul 7, 2021Updated 5 years ago
- RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, …☆499Jan 25, 2022Updated 4 years ago
- ☆70Feb 6, 2025Updated last year
- A simple program to hook the current process to identify the manual syscall executions on windows☆266Nov 18, 2022Updated 3 years ago
- FreshyCalls tries to make the use of syscalls comfortable and simple, without generating too much boilerplate and in modern C++17!☆361Sep 1, 2022Updated 3 years ago
- A copy of my Mathematics and Computer Engineering B.Sc. thesis☆19Dec 8, 2020Updated 5 years ago
- Analyze patches in a process☆262Jul 28, 2021Updated 4 years ago
- ☆27Dec 29, 2021Updated 4 years ago
- devirtualization vmprotect☆69Mar 11, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Inline syscalls made easy for windows on clang☆738Jun 21, 2024Updated 2 years ago
- Lightweight WINAPI tracing with Pin☆26Aug 22, 2019Updated 6 years ago
- DoppelGate relies on reading ntdll on disk to grab syscall stubs, and patches these syscall stubs into desired functions to bypass Userla…☆125Mar 25, 2022Updated 4 years ago
- x64 Windows kernel code execution via user-mode, arbitrary syscall, vulnerable IOCTLs demonstration☆409Jul 6, 2022Updated 4 years ago
- SyscallLoader☆11Sep 13, 2021Updated 4 years ago
- ☆42Apr 22, 2021Updated 5 years ago
- Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique☆336Jan 16, 2022Updated 4 years ago
- A kernel mode Windows rootkit in development.☆47Dec 31, 2021Updated 4 years ago
- Proof-of-Concept software for detecting AV/EDR hooks in Windows libraries.☆38May 12, 2022Updated 4 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Load and execute COFF files and Cobalt Strike BOFs in-memory☆226Sep 13, 2022Updated 3 years ago
- Recon 2015 Presentation from Alex Ionescu☆253Jan 27, 2016Updated 10 years ago
- WTSRM☆216Aug 7, 2022Updated 3 years ago
- Hookers are cooler than patches.☆170Jan 21, 2022Updated 4 years ago
- The Definitive Guide To Process Cloning on Windows☆554Jan 3, 2024Updated 2 years ago
- Load any Beacon Object File using Powershell!☆261Dec 9, 2021Updated 4 years ago
- x64 Kernel Hooks Detection☆21Jan 1, 2017Updated 9 years ago
- Universal x86/x64 VMProtect 2.0-3.X Import fixer☆31Dec 29, 2021Updated 4 years ago
- A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC☆376May 24, 2022Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- LoadLibrary for offensive operations☆1,185Oct 22, 2021Updated 4 years ago
- Monitor ETW events for Windows process mitigation policies, with stack traces☆30Oct 7, 2022Updated 3 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆160Nov 14, 2021Updated 4 years ago
- PoC: Exploit 32-bit Thread Snapshot of WOW64 to Take Over $RIP & Inject & Bypass Antivirus HIPS (HITB 2021)☆163May 27, 2021Updated 5 years ago
- PoC memory injection detection agent based on ETW, for offensive and defensive research purposes☆300Apr 10, 2021Updated 5 years ago
- An example code of CiGetCertPublisherName☆15Mar 24, 2022Updated 4 years ago
- API monitoring via return-hijacking thunks; works without information about target function prototypes.☆117May 26, 2020Updated 6 years ago