eroniko's starred repositories

safetyhook

C++23 procedure hooking library.

Language:C++License:BSL-1.0Stargazers:333Issues:0Issues:0

InfinityHookPro

InfinityHookPro Win7 -> Win11 latest

Language:C++License:MITStargazers:476Issues:0Issues:0
Language:CStargazers:5Issues:0Issues:0

dokan-delphi

Dokan Delphi Wrapper

Language:PascalLicense:MITStargazers:58Issues:0Issues:0

firmware-variables

Python library for controlling UEFI variables in Windows.

Language:PythonLicense:MITStargazers:35Issues:0Issues:0

windows-kernel-file-delete

Force a file delete using a windows kernel driver

Language:C++Stargazers:57Issues:0Issues:0

windows-kernel-file-protector

Protect a file from being deleted using windows kernel file system minifilter driver

Language:C++Stargazers:32Issues:0Issues:0

HookLib

The functions interception library written on pure C and NativeAPI with UserMode and KernelMode support

Language:CLicense:MITStargazers:714Issues:0Issues:0

IAT_patcher

Persistent IAT hooking application - based on bearparser

Language:C++License:BSD-2-ClauseStargazers:244Issues:0Issues:0

awesome-windows-kernel-security-development

windows kernel security development

Stargazers:1931Issues:0Issues:0

multiscanner

Modular file scanning/analysis framework

Language:PythonLicense:NOASSERTIONStargazers:614Issues:0Issues:0

clamwin

ClamWin Free Antivirus

Language:PythonLicense:GPL-2.0Stargazers:73Issues:0Issues:0

Blackbone

Windows memory hacking library

Language:C++License:MITStargazers:4746Issues:0Issues:0

IDTHook-x86

Detour hooking IRQ1 ISR through IDT (Interrupt Descriptor Table)

Language:C++Stargazers:16Issues:0Issues:0

inline-syscall

Inline syscalls made for MSVC supporting x64 and WOW64

Language:C++Stargazers:171Issues:0Issues:0

LightHook

Single-header, minimalistic, cross-platform hook library written in pure C

Language:C++License:MITStargazers:248Issues:0Issues:0

InfinityHook

Hook system calls, context switches, page faults and more.

Language:C++Stargazers:2354Issues:0Issues:0

IRPMon

The goal of the tool is to monitor requests received by selected device objects or kernel drivers. The tool is quite similar to IrpTracker but has several enhancements. It supports 64-bit versions of Windows (no inline hooks are used, only moodifications to driver object structures are performed) and monitors IRP, FastIo, AddDevice, DriverUnload and StartIo requests.

Language:PascalLicense:MITStargazers:357Issues:0Issues:0

DDetours

Delphi Detours Library

Language:PascalLicense:MPL-2.0Stargazers:369Issues:0Issues:0

winpwn

windows debug/exploit toolset, support user/kernel mode

Language:PythonStargazers:174Issues:0Issues:0

speakeasy

Windows kernel and user mode emulation.

Language:PythonLicense:MITStargazers:1448Issues:0Issues:0

ksh

Windows Kernel Mode Shell

Language:CLicense:MITStargazers:1Issues:0Issues:0

keval

Call arbitrary Windows kernel-mode functions from Python on another machine

Language:PythonLicense:MITStargazers:44Issues:0Issues:0

MalwLess

Test Blue Team detections without running any attack.

Language:C#License:GPL-3.0Stargazers:269Issues:0Issues:0

WindowsSpyBlocker

Block spying and tracking on Windows

Language:GoLicense:MITStargazers:4570Issues:0Issues:0

sigma

Main Sigma Rule Repository

Language:PythonLicense:NOASSERTIONStargazers:7992Issues:0Issues:0

wipedicks

Wipe files and drives securely with randoms ASCII dicks

Language:PythonLicense:MITStargazers:120Issues:0Issues:0

SecureDelete-Algorithms

A a collection of secure delete algorithms in a CLI that can be used to overwrite data in a way that makes it difficult or impossible to recover. The algorithms included in this collection are zero-fill, DoD 5220.22-M, and random data.

Language:PythonStargazers:1Issues:0Issues:0

KasperskyHook

Hook system calls on Windows by using Kaspersky's hypervisor

Language:C++License:MITStargazers:1074Issues:0Issues:0
Language:C++Stargazers:30Issues:0Issues:0