zer0mem / VadScanner
PoC of BOOST-ed _EPROCESS.VadRoot iterating
☆24Updated 10 years ago
Related projects: ⓘ
- Shareds for kernel developement☆27Updated 10 years ago
- ☆31Updated this week
- x64 Kernel Hooks Detection☆24Updated 7 years ago
- ☆29Updated this week
- Demo List cm/ps/ob/minifilter callback And Patch/Bypass it☆27Updated 6 years ago
- ☆30Updated 6 years ago
- ☆20Updated this week
- ☆13Updated 6 years ago
- Map memory to user space and manipulate user memory, using capmon☆23Updated 5 years ago
- ☆14Updated 7 years ago
- ☆28Updated this week
- Hook IDT vector 0xb2 to detect SCI in 64bit windows.☆31Updated 2 years ago
- viewing page boundaries of pages with PAGE_NOACCESS protection reveals the presence of x64dbg.☆21Updated 7 years ago
- ☆23Updated 6 years ago
- Open Source Libraries Collection☆24Updated 8 years ago
- enable libemu run pe file and add some good modify☆13Updated 5 years ago
- windows kernel File redirection☆18Updated 9 years ago
- ☆17Updated 7 years ago
- old code from 2007/2008 which uses split TLB to trace OEP☆15Updated 6 years ago
- A driverless driver that is supposed to be manually mapped, usually by using TDL exploit. The driver shows how to read/write to any proce…☆21Updated 6 years ago
- ☆17Updated this week
- ☆14Updated this week
- just an lite AntiRootkit for interesting☆23Updated 8 years ago
- ☆12Updated last month
- bypass CRC☆11Updated 6 years ago
- ☆23Updated this week
- ☆25Updated 7 years ago
- Native Development Kit for Vista 64bit And Later, by me, Based on NDK Headers 1.0, by Alex Ionescu☆16Updated 8 years ago
- ☆33Updated 3 years ago
- copy of tdifw lib☆10Updated 7 years ago