xsh3llsh0ck / PicoHook
Small driver that uses alternative syscalls feature (the project is still under development).
☆15Updated 8 months ago
Alternatives and similar repositories for PicoHook:
Users that are interested in PicoHook are comparing it to the libraries listed below
- ntoskrnl .data hooks for UM-KM communication☆36Updated 7 months ago
- POC Hook of nt!HvcallCodeVa☆50Updated last year
- PAGE_GUARD based hooking library☆42Updated 2 years ago
- Tool to dump EFI runtime drivers.☆35Updated 10 months ago
- A poc that abuses Enclave☆36Updated 2 years ago
- EFI bootkit for loading unsigned drivers☆15Updated 6 months ago
- ☆27Updated 3 months ago
- Another UEFI runtime bootkit☆28Updated last year
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆28Updated 2 months ago
- PoC kernel to usermode injection☆73Updated 10 months ago
- search for a driver/dll module that has a wanted section bigger than the size of your image☆19Updated 3 years ago
- Create stealthy, inline, EPT-like hooks using SMAP and SMEP☆35Updated 2 months ago
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆31Updated 9 months ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆49Updated last year
- A native Windows library for intercepting kernel-to-user transitions using instrumentation callbacks☆16Updated 11 months ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆42Updated last year
- Patches DSE by swapping both data ptrs located in SeValidateImageHeader && SeValidateImageData☆21Updated 11 months ago
- Windows PDB parser for kernel-mode environment.☆93Updated 2 years ago
- Kernel Level NMI Callback Blocker☆54Updated 4 months ago
- Achieving code execution through abusing vectored exception handling☆17Updated last year
- Using c++23 compile-time magic to produce obfuscated PIC strings and arrays.☆16Updated 7 months ago
- ☆32Updated last year
- 将驱动映射到会话空间☆34Updated 2 years ago
- Binary DisASseMbler☆23Updated 2 years ago