zodiacon / eBPFStudio
Work with eBPF on Windows
☆36Updated 2 months ago
Alternatives and similar repositories for eBPFStudio:
Users that are interested in eBPFStudio are comparing it to the libraries listed below
- Example of building an application verifer DLL☆46Updated 11 months ago
- Remote Thread Detection with a Kernel Driver☆30Updated 3 months ago
- Process Injection via Component Object Model (COM) IRundown::DoCallback().☆59Updated 2 years ago
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆75Updated 2 weeks ago
- Samples from my book Windows Native API programming☆61Updated this week
- A persistant Windows Service Proof of Concept, where the Service will run after Restart or Shutdown, and invoke a given software executab…☆38Updated last year
- My try to implement a virtual CPU in C☆19Updated last year
- SetWinEventHook Sample☆47Updated last year
- Detect BypassUAC using AMSI☆23Updated 2 months ago
- RPC Monitor based on The ETW Microsoft-Windows-Rpc provider☆24Updated 5 years ago
- WinDbg cheat sheet☆12Updated last year
- Finding Truth in the Shadows☆92Updated 2 years ago
- ☆30Updated last year
- Hook all callbacks which are registered with LdrRegisterDllNotification☆86Updated last month
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆117Updated last year
- View Windows System in action☆39Updated last month
- ☆38Updated last year
- Sample for Creating a new kernel object type and supporting API☆24Updated 7 months ago
- IAT-Obfuscation to make static analysis of executable harder.☆42Updated 3 years ago
- ☆25Updated 2 years ago
- ☆17Updated 9 months ago
- ☆33Updated 3 years ago
- Detours implementation (x64/x86) which used only ntdll import☆90Updated 10 months ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆63Updated 8 months ago
- ☆11Updated 4 years ago
- Demo to show how write ALPC Client & Server using native Ntdll.dll syscalls.☆21Updated 3 years ago
- Rust bindings for VMProtect.☆25Updated last year
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆38Updated 3 years ago
- Simple example for getting started with eBPF for Windows☆44Updated 2 months ago
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year