zouxianyu / BlindEye
BattlEye kernel module bypass
☆155Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for BlindEye
- ☆159Updated 2 years ago
- Some psuedo snippets from BattlEye's BEDaisy.sys loaded on Rainbow Six: Siege.☆121Updated 2 years ago
- Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL☆201Updated 4 years ago
- Loads a signed kernel driver which allows you to map any driver to kernel mode without any traces of the signed / mapped driver.☆279Updated 3 years ago
- 09/2021 reversal of EasyAntiCheat driver☆204Updated 2 years ago
- ☆171Updated last year
- The program draws with win32k gdi functions in the kernel while NtGdiDdDDISubmitCommand is being hooked.☆251Updated 4 years ago
- Easy Anti PatchGuard☆214Updated 3 years ago
- ☆194Updated last year
- Drawing from kernelmode without any hooks☆159Updated 2 years ago
- a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.☆142Updated 2 months ago
- r/w virtual memory without attach☆152Updated last year
- ☆143Updated 2 years ago
- ☆150Updated 6 months ago
- ☆212Updated 2 years ago
- ☆132Updated 10 months ago
- Code for Battleyes shellcode☆212Updated 3 years ago
- Check your detection vectors☆137Updated this week
- undetected eac mapper☆163Updated 2 years ago
- Kernel dwm render☆127Updated last year
- Detect-KeAttachProcess by iterating through all processes as well as checking the context of the thread.☆110Updated 2 years ago
- base for testing☆156Updated last month
- Manual mapper that uses PTE manipulation, Virtual Address Descriptor (VAD) manipulation, and forceful memory allocation to hide executabl…☆290Updated 2 years ago
- BattlEye shellcodes tester☆136Updated 2 years ago
- ☆139Updated 3 years ago
- x64 Windows kernel driver mapper, inject unsigned driver using anycall☆115Updated 9 months ago
- manually map driver for a signed driver memory space☆138Updated 3 years ago
- Kernel driver that .text hooks a syscall in dxgkrnl.sys which can be called from our user-mode client to send instructions like rpm/wpm a…☆147Updated last year
- Archive R/W into any protected process by changing the value of KTHREAD->PreviousMode☆146Updated 2 years ago