CrackerCat / VirtualDbgHide

Windows kernel mode driver to prevent detection of debuggers.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

VirtualDbgHide

Windows kernel mode driver using Intel's hardware virtualization to hook MSR_LSTAR (system call handler). Currently bypasses PatchGuard on Windows 8.1.

About

Windows kernel mode driver to prevent detection of debuggers.


Languages

Language:C 52.7%Language:C++ 40.9%Language:Assembly 6.3%Language:Makefile 0.0%