zodiacon / eBPFStudio
Work with eBPF on Windows
☆35Updated last month
Alternatives and similar repositories for eBPFStudio:
Users that are interested in eBPFStudio are comparing it to the libraries listed below
- Example of building an application verifer DLL☆45Updated 10 months ago
- Process Injection via Component Object Model (COM) IRundown::DoCallback().☆58Updated 2 years ago
- Detect BypassUAC using AMSI☆22Updated last month
- Samples from my book Windows Native API programming☆60Updated last week
- Finding Truth in the Shadows☆89Updated 2 years ago
- 32 bit process inject shellcode to 32 bit process and 64 bit process☆29Updated last year
- My try to implement a virtual CPU in C☆19Updated last year
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆112Updated last year
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆56Updated 6 months ago
- Remote Thread Detection with a Kernel Driver☆29Updated 2 months ago
- Windows PDB Parser using Imagehlp library.☆16Updated 2 years ago
- Call NtCreateUserProcess directly as normal.☆68Updated 2 years ago
- ☆37Updated last year
- shellcode生成框架☆84Updated 8 months ago
- RPC Monitor based on The ETW Microsoft-Windows-Rpc provider☆24Updated 5 years ago
- An implementation of an indirect system call☆123Updated last year
- ☆30Updated last year
- A COFF Loader written in Rust☆63Updated this week
- Windows API Call Obfuscation☆99Updated 2 years ago
- DLL 转发工具方法。☆51Updated last year
- Command line interface for (running) BOFs☆43Updated this week
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆38Updated 3 years ago
- Windows Defender VDM lua collections☆47Updated 2 years ago
- A compact tool for detecting AV/EDR hooks in default Windows libraries.☆31Updated 2 years ago
- Different tools for Microsoft Hyper-V researching☆49Updated 9 months ago
- A persistant Windows Service Proof of Concept, where the Service will run after Restart or Shutdown, and invoke a given software executab…☆38Updated last year
- SetWinEventHook Sample☆46Updated last year
- Standalone Metasploit-like XOR encoder for shellcode☆47Updated 10 months ago
- https://key08.com/index.php/2021/10/19/1375.html☆66Updated 2 years ago
- Hook all callbacks which are registered with LdrRegisterDllNotification☆85Updated 2 years ago