内核级ARK工具。
☆62Aug 1, 2016Updated 9 years ago
Alternatives and similar repositories for Anti-Rootkits
Users that are interested in Anti-Rootkits are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆17Mar 3, 2016Updated 10 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Aug 12, 2015Updated 10 years ago
- Demo List cm/ps/ob/minifilter callback And Patch/Bypass it☆29Dec 5, 2017Updated 8 years ago
- Windows设备驱动开发 光盘(示例代码)☆10Jan 14, 2013Updated 13 years ago
- ☆36Oct 29, 2020Updated 5 years ago
- The project is a demo solution for one of the anti-rootkit techniques aimed on overcoming splicers☆34Mar 13, 2017Updated 9 years ago
- windows kernel File redirection☆20Sep 21, 2014Updated 11 years ago
- An ark tool's driver☆40May 11, 2017Updated 8 years ago
- Windows Ark 工具的工程和一些demo☆193Mar 6, 2016Updated 10 years ago
- Wow64 syscall hook☆43May 28, 2017Updated 8 years ago
- An Ark tool project,run on Win7 x86/x64☆118Jul 11, 2017Updated 8 years ago
- pass game protect☆12Apr 26, 2014Updated 11 years ago
- A command line tool to load and unload a device driver.☆46Jun 10, 2017Updated 8 years ago
- A-Protect Anti Rootkit Tool☆57Jan 21, 2014Updated 12 years ago
- Modify process handle permissions☆61Nov 30, 2016Updated 9 years ago
- createfile☆50Oct 27, 2015Updated 10 years ago
- ☆17Oct 24, 2016Updated 9 years ago
- x64 Kernel Hooks Detection☆24Jan 1, 2017Updated 9 years ago
- An aggregate of tools used in the core of vmp_dbg plus other parsing utils to parse vmp bc.☆16Oct 18, 2016Updated 9 years ago
- more at http://www.zer0mem.sk/?p=271☆12Jun 11, 2013Updated 12 years ago
- Block process execute kernel driver for Windows x64☆19Apr 7, 2016Updated 9 years ago
- ☆18Sep 27, 2016Updated 9 years ago
- RootKit & Cheat Scanner - Windows☆225Aug 9, 2019Updated 6 years ago
- A sample on how to inject a DLL from a kernel driver☆61Sep 13, 2016Updated 9 years ago
- C++ wrapper for the Windows structured storage implementation known as Compound Files☆20Aug 30, 2020Updated 5 years ago
- ☆14Aug 15, 2018Updated 7 years ago
- Hidden kernel mode code execution for bypassing modern anti-rootkits.☆85Dec 23, 2010Updated 15 years ago
- IDA反-反调试插件 IDAStealth v1.3.3, created 06/28/2011, Jan Newger☆21Apr 4, 2018Updated 7 years ago
- Windbg extension to find PatchGuard pages☆123Jun 24, 2014Updated 11 years ago
- 逆向火绒安全软件驱动——sysdiag☆158Jan 15, 2018Updated 8 years ago
- Шаблон полнофункционального драйвера и обёртки над ядерным API☆113Aug 28, 2016Updated 9 years ago
- Sysark全称system anti-rootkit,是我学习内核写的工具(2013年的代码,后续不会再更新),里面基本上所有的功能都是用内核实现的。这里只是实现了反rootkit部分功能,作为工具的话,本人觉得还欠完善,但作为学习,或有人需要。目前针对的是XP SP2,…☆27Dec 26, 2017Updated 8 years ago
- network filter driver that control network send speed, based on windows tdi framework.☆31Feb 16, 2024Updated 2 years ago
- Notes my learning steps about Windows-NT☆23May 18, 2017Updated 8 years ago
- Windows kernel-mode callbacks tutorial driver☆48Aug 8, 2016Updated 9 years ago
- A Win32 logger based on DebugView & ETW.☆16Nov 15, 2017Updated 8 years ago
- ☆48Nov 7, 2018Updated 7 years ago
- The dll that can hide itself and then delete itselft.☆32Mar 31, 2013Updated 12 years ago
- Remote execution tool☆14Jan 14, 2014Updated 12 years ago