stdhu's repositories
al-khaser
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
Awesome-Backbones
Integrate deep learning models for image classification | Backbone learning/comparison/magic modification project
BlackLotus
BlackLotus UEFI Windows Bootkit
Cerberus
A C++ tool to unstrip Rust/Go binaries (ELF and PE)
efi-monitor
just proof of concept. hooking MmCopyMemory PG safe.
EfiGuard
Disable PatchGuard and DSE at boot time
enum_real_dirbase
从MmPfnData中枚举进程和页目录基址
ETWProcessMon2
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
json
JSON for Modern C++
kcrypt
an encryption library designed for Windows kernel and driver programming
KernelDwm
Kernel dwm render
oxgenPdb
a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.
ProcessHider
Post-exploitation tool for hiding processes from monitoring applications
qemu-anti-detection
A patch to hide qemu itself, bypass mhyprot,EAC,nProtect / VMProtect,VProtect, Themida, Enigma Protector,Safegine Shielden
R3nzSkin
Skin changer for League of Legends (LOL)
r77-rootkit
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
ReadPhys
r/w virtual memory without attach
RmTools
蓝队应急工具
rules
Repository of yara rules
Sandboxie
Sandboxie Plus & Classic
SymbolicAccess
Static user/kernel mode library that allows access to all functions and global variables by extracting offsets from the PDB
tp-emulator
A basic 100 loc CPU emulator using the existing code of ntoskrnl.exe
UEDumper
The all in one Unreal Engine Dumper and editor for UE 4.19 - 5.2
unicorn-whpx
跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式提供了另一种CPU指令的模拟方式,在保持原有unicorn导出接口不变的情况下,采用Hyper-v支持带硬件虚拟化支持的Windows Hypervisor Platform API接口扩展了底层CPU模拟环境实现,支持X86指令集二进制程序模拟平台和调试器.
Valorant-External
Valorant Cheat | Aimbot + Esp + Skin Changer
VMPilot
VMPilot: A Modern C++ Virtual Machine SDK
vxlang-page
protector & obfuscator & code virtualizer