zodiacon / VerifierDLL
Example of building an application verifer DLL
☆44Updated 5 months ago
Related projects ⓘ
Alternatives and complementary repositories for VerifierDLL
- SetWinEventHook Sample☆41Updated last year
- Finding Truth in the Shadows☆84Updated last year
- Easy encrypt/decrypt data with TPM☆24Updated 8 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆49Updated last year
- break link between dll and it file on disk☆11Updated 2 months ago
- Rust bindings to the System Informer's (formerly known as Process Hacker) "phnt" native Windows headers☆39Updated 2 months ago
- Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE☆64Updated last year
- In-memory hiding technique☆42Updated 5 months ago
- Enabled / Disable LSA Protection via BYOVD☆62Updated 2 years ago
- ☆14Updated 3 months ago
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections☆96Updated last year
- ☆27Updated 2 years ago
- Sample for Creating a new kernel object type and supporting API☆22Updated 2 months ago
- Demo from the Malware Analysis and Development Webinar☆19Updated 7 months ago
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆49Updated last year
- silence file system monitoring components by hooking their minifilters☆51Updated 9 months ago
- Native Powers Talk demos☆14Updated last year
- ☆27Updated 4 months ago
- Detours implementation (x64/x86) which used only ntdll import☆88Updated 5 months ago
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆28Updated 2 years ago
- ☆98Updated 2 years ago
- A VMWare logger using built-in backdoor.☆25Updated last month
- PoC exploit for HP Hardware Diagnostic's EtdSupp driver☆50Updated last year
- Rust version of the objdir tool☆12Updated 8 months ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆47Updated 2 months ago
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆33Updated 11 months ago
- Hook all callbacks which are registered with LdrRegisterDllNotification☆83Updated last year
- ☆13Updated last year
- Windows PDB Parser using Imagehlp library.☆16Updated 2 years ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆30Updated last year