꿀보's repositories
antispy
AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its assistance,you can easily spot and neutralize malwares hidden from normal detectors.
Blackbone
Windows memory hacking library
CallbackObjectAnalyzer
Dumps information about all the callback objects found in a dump file and the functions registered for them
ceload
Loading dbk64.sys and grabbing a handle to it
CosMapper
Loads a signed kernel driver which allows you to map any driver to kernel mode without any traces of the signed / mapped driver.
DarkLoadLibrary
LoadLibrary for offensive operations
dwmhook
noob hooking dwm for overlay
EventTranscript.db-Research
A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
face-injector-v2
update face injector by KANKOSHEV
herpaderping
Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of a process.
II-ExternalHookingLib
External Hooking ( Bypasss process byte patching checks | Injector included )
kdmapper-1
KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory
kernel-csgo
Kernel cheat with kernel hook for communication
KernelBypassSharp
C# Kernel Mode Driver to read and write memory in protected processes
KernelSharp
C# Kernel Mode Driver example using NativeAOT
KernelV
Rootkit & Anti-rootkit
medusa
Binary instrumentation framework based on FRIDA
ollvm-13
obfuscator-llvm 移植到llvm13
pagewalkr
An x64 page table iterator written in C++ as a kernel mode windows driver.
runtimelab
This repo is for experimentation and exploring new ideas that may or may not make it into the main dotnet/runtime repo.
Shh0yaUEDumper
UEDumper
UE3SDKGenerator
Internal SDK generator for Unreal Engine 3 games.
VXUG-Papers
Research code & papers from members of vx-underground.
wil
Windows Implementation Library
Windows10EtwEvents
Events from all manifest-based and mof-based ETW providers across Windows 10 versions
ZeroKernel
Bringing kernel driver to C# with MichalStrehovsky's zerosharp