zodiacon / DllInjectionWithThreadContextLinks
This is a sample that shows how to leverage SetThreadContext for DLL injection
☆84Updated 7 years ago
Alternatives and similar repositories for DllInjectionWithThreadContext
Users that are interested in DllInjectionWithThreadContext are comparing it to the libraries listed below
Sorting:
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆57Updated 6 years ago
- Analyze and attack windows applications using dll hijacking vulnerabilities☆58Updated 5 years ago
- Standalone program to download PDB Symbol files for debugging without WDK☆79Updated 6 years ago
- An Attempt to Bypass Memory Scanners By Misusing the ntdll.dll "RT" Section.☆96Updated 9 years ago
- ☆26Updated 7 years ago
- C++☆80Updated 8 years ago
- A minifilter driver preserves all modified and deleted files.☆80Updated 10 years ago
- ☆47Updated 8 years ago
- ☆36Updated 8 years ago
- win10 pgContext dynamic dump (btc version)☆107Updated 5 years ago
- Protects deletion of files with a specified extension using a kernel-mode driver.☆76Updated 7 years ago
- kernel-mode TDI client which can send and receive HTTP requests☆55Updated 7 years ago
- 内核级ARK工具。☆59Updated 9 years ago
- Advance LPC☆70Updated 8 years ago
- WinDbg debugger extension library providing various tools to analyse, dump and fix (restore) Microsoft Portable Executable files for both…☆84Updated last year
- PoC for detecting and dumping process hollowing code injection☆52Updated 6 years ago
- Anti-Anti-VM solution via Windows Driver☆59Updated 7 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆79Updated 14 years ago
- ☆54Updated 8 years ago
- Polymorphic Stub Creator☆34Updated 8 years ago
- An ark tool's driver☆40Updated 8 years ago
- Simple proof of concept code for injecting libraries on 64bit processes from a 32bit process☆96Updated 6 years ago
- PE(compressed dll) memory loader using nt api☆44Updated 8 years ago
- Reflective PE loader for DLL injection☆180Updated 7 years ago
- Code injection by hijacking threads in Windows 32-bit applications☆43Updated 6 years ago
- LSASS INJECTOR☆35Updated 6 years ago
- Simple driver to register all available process, thread, image, Registry, and Object callbacks☆123Updated 7 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- This program can retrieve signature information from PE files which signed by one or more certificates on Windows. Supporting multi-signe…☆101Updated 2 years ago
- C++ 17 compile time string encryption supporting vs2010-2019☆74Updated 5 years ago