zodiacon / RemoteThreadDetection
Remote Thread Detection with a Kernel Driver
☆27Updated last month
Alternatives and similar repositories for RemoteThreadDetection:
Users that are interested in RemoteThreadDetection are comparing it to the libraries listed below
- Example of building an application verifer DLL☆44Updated 8 months ago
- SetWinEventHook Sample☆46Updated last year
- Demo from the Malware Analysis and Development Webinar☆19Updated 10 months ago
- Finding Truth in the Shadows☆88Updated 2 years ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆54Updated 5 months ago
- silence file system monitoring components by hooking their minifilters☆54Updated last year
- ☆25Updated 2 years ago
- List the ETW provider(s) in the registration table of a process.☆56Updated last year
- Youtube channel sample code☆40Updated last month
- Samples from my book Windows Native API programming☆59Updated 7 months ago
- ☆82Updated 8 months ago
- Native Powers Talk demos☆14Updated last year
- HEVD Exploit: ArbitraryWrite on Windows 10 22H2 - Bypassing KVA Shadow and SMEP via PML4 Entry Manipulation☆22Updated 7 months ago
- https://github.com/janoglezcampos/c_syscalls with the ASM rewritten by myself for Visual Studio's Compiler.☆30Updated 7 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆52Updated 2 years ago
- ☆16Updated last year
- Easy encrypt/decrypt data with TPM☆25Updated 11 months ago
- Research of modifying exported function names at runtime (C/C++, Windows)☆17Updated 8 months ago
- Sample for Creating a new kernel object type and supporting API☆23Updated 5 months ago
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆26Updated 6 months ago
- Next gen process injection technique☆44Updated 4 years ago
- Detours implementation (x64/x86) which used only ntdll import☆90Updated 8 months ago
- ☆36Updated this week
- ☆19Updated 2 months ago
- Hook all callbacks which are registered with LdrRegisterDllNotification☆84Updated 2 years ago
- In-memory hiding technique☆45Updated last month
- Repository of Microsoft Driver Block Lists based off of OS-builds☆39Updated 10 months ago
- Listing UDP connections with remote address without sniffing.☆30Updated last year
- ☆13Updated last month
- Exploiting the KsecDD Windows driver through Server Silos☆50Updated 3 months ago