zodiacon / TraceConnections
Simple example for getting started with eBPF for Windows
☆44Updated last month
Alternatives and similar repositories for TraceConnections:
Users that are interested in TraceConnections are comparing it to the libraries listed below
- Example of building an application verifer DLL☆45Updated 9 months ago
- Remote Thread Detection with a Kernel Driver☆29Updated 2 months ago
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- Sample for Creating a new kernel object type and supporting API☆23Updated 6 months ago
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆26Updated 2 years ago
- Proof-of-concept game using VBS enclaves to protect itself from cheating☆39Updated 4 months ago
- Samples from my book Windows Native API programming☆60Updated this week
- anti-ransomware file-system filter☆57Updated 6 months ago
- Different tools for Microsoft Hyper-V researching☆49Updated 9 months ago
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆71Updated 5 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆51Updated 2 years ago
- ☆29Updated last month
- ☆70Updated 2 years ago
- Finding Truth in the Shadows☆89Updated 2 years ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆56Updated 6 months ago
- Easy encrypt/decrypt data with TPM☆25Updated last year
- Code samples that serve as references for Windows API functions☆30Updated 10 months ago
- Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE☆65Updated last year
- Hook all callbacks which are registered with LdrRegisterDllNotification☆85Updated 2 years ago
- Rust version of the objdir tool☆12Updated last year
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆73Updated last year
- Youtube channel sample code☆48Updated last week
- Generate a PDB file given the old PDB file and an address mapping☆42Updated 2 weeks ago
- bypassing intel txt's tboot integrity checks via coreboot shim☆64Updated 2 weeks ago
- ☆15Updated 7 months ago
- Header-only C++ library for producing PE files.☆31Updated last year
- SetWinEventHook Sample☆46Updated last year
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- Detours implementation (x64/x86) which used only ntdll import☆90Updated 9 months ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆47Updated this week