xu-Wan / HypercallPageHookView external linksLinks
POC Hook of nt!HvcallCodeVa
☆54May 8, 2023Updated 2 years ago
Alternatives and similar repositories for HypercallPageHook
Users that are interested in HypercallPageHook are comparing it to the libraries listed below
Sorting:
- Not mine. Only for saving☆26Jun 28, 2022Updated 3 years ago
- ☆34Apr 11, 2023Updated 2 years ago
- ☆23May 8, 2023Updated 2 years ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆133Apr 26, 2023Updated 2 years ago
- ☆159May 21, 2024Updated last year
- Detect removed thread from PspCidTable.☆75Mar 18, 2022Updated 3 years ago
- Old way for blocking NMI interrupts☆29Sep 6, 2022Updated 3 years ago
- Mapping your code on a 0x1000 size page☆71May 20, 2022Updated 3 years ago
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆159Apr 13, 2023Updated 2 years ago
- ☆23Jul 24, 2023Updated 2 years ago
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆51Mar 11, 2021Updated 4 years ago
- base for testing☆186Sep 28, 2024Updated last year
- just proof of concept. hooking MmCopyMemory PG safe.☆81Nov 13, 2023Updated 2 years ago
- A kernel module dumper for Windows x64 using mhyprot vulnerable driver☆37Oct 26, 2020Updated 5 years ago
- ☆144Dec 10, 2022Updated 3 years ago
- ☆73Aug 31, 2022Updated 3 years ago
- Reverse Engineering a signed kernel driver packed and virtualized with VMProtect 3.6☆105Apr 28, 2023Updated 2 years ago
- Walks through the 4-level paging structures in Windows x64☆13Feb 12, 2023Updated 3 years ago
- Bypasses for Windows kernel callbacks PatchGuard protection☆44Aug 15, 2021Updated 4 years ago
- 基于Intel-VT技术的windows内核增强型驱动☆30Jun 9, 2022Updated 3 years ago
- Hijack NotifyRoutine for a kernelmode thread☆41Jun 4, 2022Updated 3 years ago
- 从MmPfnData中枚举进程和页目录基址☆206Aug 18, 2023Updated 2 years ago
- x64 assembler library☆31Jun 7, 2024Updated last year
- Portable & Custmizable Windows Defender☆13Nov 10, 2021Updated 4 years ago
- ☆193May 1, 2023Updated 2 years ago
- Hook NtDeviceIoControlFile with PatchGuard☆107May 10, 2022Updated 3 years ago
- hidden_syscall - syscaller without using syscall instruction in code☆62Jan 23, 2023Updated 3 years ago
- mouseclassservicecallback detection via hook☆52Feb 7, 2022Updated 4 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆365Aug 18, 2022Updated 3 years ago
- ☆29Dec 29, 2022Updated 3 years ago
- Intercepting DeviceControl via WPP☆138Nov 18, 2019Updated 6 years ago
- The kernel mode Standard Template Library Template☆19Feb 22, 2020Updated 5 years ago
- windows kernel pagehook☆41Oct 30, 2022Updated 3 years ago
- ☆223Mar 11, 2023Updated 2 years ago
- 🪝 Various EPT hook detection approaches☆143Jul 29, 2025Updated 6 months ago
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆119Feb 8, 2022Updated 4 years ago
- ☆63Sep 28, 2022Updated 3 years ago
- Example of reading process memory through kernel special APC☆110Apr 21, 2023Updated 2 years ago
- ☆29Mar 9, 2024Updated last year