zodiacon / RemoteThreadDetection
Remote Thread Detection with a Kernel Driver
☆28Updated 2 months ago
Alternatives and similar repositories for RemoteThreadDetection:
Users that are interested in RemoteThreadDetection are comparing it to the libraries listed below
- Example of building an application verifer DLL☆45Updated 9 months ago
- SetWinEventHook Sample☆46Updated last year
- Demo from the Malware Analysis and Development Webinar☆20Updated 11 months ago
- silence file system monitoring components by hooking their minifilters☆56Updated last year
- Finding Truth in the Shadows☆89Updated 2 years ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆56Updated 6 months ago
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆112Updated last year
- Detours implementation (x64/x86) which used only ntdll import☆90Updated 9 months ago
- Samples from my book Windows Native API programming☆60Updated last month
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections☆118Updated last year
- ☆15Updated 7 months ago
- ☆37Updated last month
- ☆13Updated 2 months ago
- Proof-of-concept game using VBS enclaves to protect itself from cheating☆39Updated 4 months ago
- ☆16Updated 2 years ago
- Easy encrypt/decrypt data with TPM☆25Updated last year
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆73Updated last year
- Sample for Creating a new kernel object type and supporting API☆23Updated 6 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆51Updated 2 years ago
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆97Updated last year
- Header-only C++ library for producing PE files.☆31Updated last year
- A simple direct syscall wrapper written in C++ with compatibility for x86 and x64 programs.☆45Updated last month
- Hook all callbacks which are registered with LdrRegisterDllNotification☆85Updated 2 years ago
- Next gen process injection technique☆45Updated 4 years ago
- windows rootkit☆58Updated 10 months ago
- A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.☆109Updated 3 years ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆117Updated last year
- In-memory hiding technique☆47Updated 2 months ago
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆154Updated last year
- ☆70Updated 2 years ago