zodiacon / eBPFStudioLinks
Work with eBPF on Windows
☆37Updated 3 months ago
Alternatives and similar repositories for eBPFStudio
Users that are interested in eBPFStudio are comparing it to the libraries listed below
Sorting:
- Example of building an application verifer DLL☆46Updated last year
- Remote Thread Detection with a Kernel Driver☆30Updated 5 months ago
- My try to implement a virtual CPU in C☆19Updated last year
- RPC Monitor based on The ETW Microsoft-Windows-Rpc provider☆24Updated 5 years ago
- Process Injection via Component Object Model (COM) IRundown::DoCallback().☆60Updated 2 years ago
- Windows PDB Parser using Imagehlp library.☆16Updated 2 years ago
- Detect BypassUAC using AMSI☆23Updated 4 months ago
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆77Updated last month
- 32 bit process inject shellcode to 32 bit process and 64 bit process☆34Updated 2 years ago
- ☆33Updated 3 years ago
- Finding Truth in the Shadows☆95Updated 2 years ago
- SetWinEventHook Sample☆48Updated last year
- An implementation of an indirect system call☆129Updated last year
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆63Updated 9 months ago
- defender_database☆18Updated last year
- Download pdbs from symbol servers and cache locally, parse symbol paths from env vars☆22Updated 3 months ago
- Different tools for Microsoft Hyper-V researching☆57Updated last year
- A years-old exploit of a local EoP vulnerability in Kingsoft Antivirus KWatch Driver version 2009.3.17.77.☆38Updated 3 years ago
- A fully compatible replacement of Windows NT NtCreateLowBoxToken syscall - precisely restored from reverse engineering☆38Updated last week
- API Set Viewer☆89Updated 5 months ago
- A universal binary patching dll.☆89Updated 8 months ago
- Generate a PDB file given the old PDB file and an address mapping☆48Updated 3 months ago
- Call NtCreateUserProcess directly as normal.☆71Updated 3 years ago
- Rust bindings for VMProtect.☆26Updated last year
- WinDbg installer/updater☆41Updated last year
- Hook all callbacks which are registered with LdrRegisterDllNotification☆87Updated 2 months ago
- Sample for Creating a new kernel object type and supporting API☆24Updated 9 months ago
- 参考taviso的代码逆向一下mpengine.dll☆19Updated 2 years ago
- Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE☆65Updated 2 years ago
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆56Updated this week