xiaobfly / MemPELinks
一种通用的XOR加密后内存加载PE绕过杀毒软件的方法
☆11Updated 9 years ago
Alternatives and similar repositories for MemPE
Users that are interested in MemPE are comparing it to the libraries listed below
Sorting:
- ☆25Updated 4 years ago
- 进程保护、进程过滤的小工程、主要亮点是在内核中对操作系统中的用户进行管理☆16Updated 10 years ago
- x64HOOK库☆18Updated 5 years ago
- DllInject (Memory Load)☆10Updated 6 years ago
- 进程行为分析工具☆14Updated 8 years ago
- ☆40Updated 5 years ago
- Windows NDIS 6.3 Protocol Driver that provides usermode access to an IsoSwitch or CrowdSwitch☆10Updated 7 years ago
- 卓然主动防御源码(可执行文件+完整源码+完整作品报告)☆15Updated 6 years ago
- Https中间人劫持验证性库☆17Updated 8 years ago
- 无模块注入工程 VS2008☆11Updated 6 years ago
- Demo List cm/ps/ob/minifilter callback And Patch/Bypass it☆28Updated 7 years ago
- Windows内核设计思想☆23Updated 8 years ago
- Automatically exported from code.google.com/p/guardlite☆11Updated 9 years ago
- x64 Kernel Hooks Detection☆24Updated 8 years ago
- PE文件解析和加壳工具☆18Updated 2 years ago
- Kernel Inject Process☆11Updated 7 years ago
- Sysark全称system anti-rootkit,是我学习内核写的工具(2013年的代码,后续不会再更新),里面基本上所有的功能都是用内核实现的。这里只是实现了反rootkit部分功能,作为工具的话,本人觉得还欠完善,但作为学习,或有人需要。目前针对的是XP SP2,…☆27Updated 7 years ago
- 谷歌2011年开始开发的一款专注于速度的压缩,解压库,速度完胜zlib。☆14Updated 7 years ago
- 粗暴地枚举管理内核的WFP对象。 Manage kernel WFPs in a brutal way.☆27Updated 7 years ago
- Locked home page for Internet Explorer.☆20Updated 11 years ago
- 管道监视器,类似于spyxx之类的东西,一般用于监视目标进程的系统调用.关键词:detours+piep☆23Updated 11 years ago
- lz77win sources!lz77 is the compression software for the windows platform.☆24Updated 6 years ago
- 基于WinDivert实现的一个包过滤与截断程序☆13Updated 6 years ago
- 稳定多线程中的inline hook☆16Updated 5 years ago
- PDB Explorer 是一个能够查看微软 pdb 文件(Program DataBase,程序数据库)的工具,它能够将 pdb 文件中的 struct、union 及 enum 类型的定义以 C/C++ 的语法显示出来,特别适合 Windows 底层研究人员及 DDK …☆37Updated 10 years ago
- Basic Injector running on x64 machines that is able to load into x64 AND x86 processes☆21Updated 6 years ago
- windows kernel File redirection☆20Updated 10 years ago
- 锁主页驱动☆37Updated 6 years ago
- Enables x64 applications to call any x86 function through a special function called X86Call☆17Updated 8 years ago
- 安全卫士项目☆32Updated 7 years ago