Signal-Labs / iat_unhook_sample

(First Public?) Sample of unhooking ntdll (All Exports & IAT imports) hooks in Rust using in-memory disassembly, avoiding direct syscalls and all hooked functions (incl. hooked NtProtectVirtualMemory)

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Signal-Labs/iat_unhook_sample Stargazers