zodiacon / winnativeapibooksamples
Samples from my book Windows Native API programming
☆57Updated 4 months ago
Related projects ⓘ
Alternatives and complementary repositories for winnativeapibooksamples
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆47Updated 2 months ago
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections☆95Updated last year
- Example of building an application verifer DLL☆44Updated 5 months ago
- Hook all callbacks which are registered with LdrRegisterDllNotification☆83Updated last year
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆49Updated last year
- Finding Truth in the Shadows☆84Updated last year
- Detours implementation (x64/x86) which used only ntdll import☆88Updated 5 months ago
- Reverse engineering winapi function loadlibrary.☆70Updated last year
- PoC exploit for HP Hardware Diagnostic's EtdSupp driver☆50Updated last year
- ☆27Updated 2 years ago
- Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)☆20Updated 4 years ago
- ☆98Updated 2 years ago
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆100Updated last year
- Call NtCreateUserProcess directly as normal.☆66Updated 2 years ago
- Dynamically generated obfuscated jumps and/or function calls☆33Updated last year
- Compact MBR Bootkit for Windows☆44Updated 2 years ago
- Enabled / Disable LSA Protection via BYOVD☆62Updated 2 years ago
- APC DLL Injector with NtQueueApcThread and wake up thread support☆44Updated 7 years ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆48Updated last year
- A x64 PE Packer/Protector Developed in C++ and VisualStudio☆50Updated last year
- An initial proof of concept of a bootkit based on Cr4sh's DMABackdoorBoot☆59Updated last year
- ☆84Updated 5 months ago
- Next gen process injection technique☆42Updated 4 years ago
- ☆106Updated last year
- ☆22Updated last year
- Files for http://blog.deniable.org/posts/windows-callbacks/☆67Updated 2 years ago
- This script is used to unload PsSetCreateProcessNotifyRoutineEx, PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine and PsSetCr…☆62Updated 9 months ago
- A PoC for adding NtContinue to CFG allowed list in order to make Ekko work in a CFG protected process☆87Updated 2 years ago
- Minifilter Callback Patching Proof-of-Concept☆62Updated 2 years ago
- ☆67Updated last year