stdhu's repositories

cpp-ipc

C++ IPC Library: A high-performance inter-process communication using shared memory on Linux/Windows.

Language:C++License:NOASSERTIONStargazers:1Issues:0Issues:0

al-khaser

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

Language:C++License:GPL-2.0Stargazers:0Issues:0Issues:0

Awesome-Backbones

Integrate deep learning models for image classification | Backbone learning/comparison/magic modification project

Language:PythonStargazers:0Issues:0Issues:0

BlackLotus

BlackLotus UEFI Windows Bootkit

Language:CStargazers:0Issues:0Issues:0

Cerberus

A C++ tool to unstrip Rust/Go binaries (ELF and PE)

Language:C++License:MITStargazers:0Issues:0Issues:0

efi-monitor

just proof of concept. hooking MmCopyMemory PG safe.

Language:CStargazers:0Issues:0Issues:0

EfiGuard

Disable PatchGuard and DSE at boot time

Language:C++License:GPL-3.0Stargazers:0Issues:0Issues:0

enum_real_dirbase

从MmPfnData中枚举进程和页目录基址

Language:C++Stargazers:0Issues:0Issues:0

ETWProcessMon2

ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.

Language:C#Stargazers:0Issues:0Issues:0

json

JSON for Modern C++

Language:C++License:MITStargazers:0Issues:0Issues:0

kcrypt

an encryption library designed for Windows kernel and driver programming

Language:C++Stargazers:0Issues:0Issues:0

KernelDwm

Kernel dwm render

Language:C++License:MITStargazers:0Issues:0Issues:0

oxgenPdb

a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.

Language:C++Stargazers:0Issues:0Issues:0

ProcessHider

Post-exploitation tool for hiding processes from monitoring applications

Language:C++Stargazers:0Issues:0Issues:0

qemu-anti-detection

A patch to hide qemu itself, bypass mhyprot,EAC,nProtect / VMProtect,VProtect, Themida, Enigma Protector,Safegine Shielden

Stargazers:0Issues:0Issues:0

R3nzSkin

Skin changer for League of Legends (LOL)

Language:C++License:MITStargazers:0Issues:0Issues:0

r77-rootkit

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Language:CLicense:BSD-2-ClauseStargazers:0Issues:0Issues:0

ReadPhys

r/w virtual memory without attach

Language:C++License:GPL-3.0Stargazers:0Issues:0Issues:0

RmTools

蓝队应急工具

Language:YARALicense:MITStargazers:0Issues:0Issues:0

rules

Repository of yara rules

Language:YARALicense:GPL-2.0Stargazers:0Issues:0Issues:0

Sandboxie

Sandboxie Plus & Classic

Language:CLicense:GPL-3.0Stargazers:0Issues:0Issues:0

SymbolicAccess

Static user/kernel mode library that allows access to all functions and global variables by extracting offsets from the PDB

Language:C++License:MITStargazers:0Issues:0Issues:0

tp-emulator

A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe

Language:C++License:MITStargazers:0Issues:0Issues:0

UEDumper

The all in one Unreal Engine Dumper and editor for UE 4.19 - 5.2

Language:C++License:MITStargazers:0Issues:0Issues:0

unicorn-whpx

跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式提供了另一种CPU指令的模拟方式,在保持原有unicorn导出接口不变的情况下,采用Hyper-v支持带硬件虚拟化支持的Windows Hypervisor Platform API接口扩展了底层CPU模拟环境实现,支持X86指令集二进制程序模拟平台和调试器.

Language:CStargazers:0Issues:0Issues:0

Valorant-External

Valorant Cheat | Aimbot + Esp + Skin Changer

Language:C++Stargazers:0Issues:0Issues:0

VMPilot

VMPilot: A Modern C++ Virtual Machine SDK

Language:C++License:Apache-2.0Stargazers:0Issues:0Issues:0

vxlang-page

protector & obfuscator & code virtualizer

Language:C++Stargazers:0Issues:0Issues:0
Language:C++Stargazers:0Issues:0Issues:0
Language:PythonStargazers:0Issues:0Issues:0