try2crack's repositories
antispy
AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its assistance,you can easily spot and neutralize malwares hidden from normal detectors.
bitvisor
A git clone of the official mercurial repository
BLUESPAWN
An Active Defense and EDR software to empower Blue Teams
darwin-xnu
The Darwin Kernel (mirror)
DdiMon
Monitoring and controlling kernel API calls with stealth hook using EPT
Detours
Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
dnslib
Simple C++ library designed for encoding and decoding of DNS protocol packets
etw-providers-docs
Document ETW providers
hollows_hunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
HyperPlatform
Intel VT-x based hypervisor aiming to provide a thin VM-exit filtering platform on Windows.
injdrv
proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC
IPC
IPC is a C++ library that provides inter-process communication using shared memory on Windows. A .NET wrapper is available which allows interaction with C++ as well.
Kernel-Bridge
Windows kernel hacking framework, driver template, hypervisor and API written on C++
krabsetw
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
KTL
Kernel Template Library: STL-style containers and tools for Windows kernel space programming
libpeconv
A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl
messageanalyzer-archive
Microsoft Message Analyzer EOL Archive
OLLVM_Deobfuscation
OLLVM_Deobfuscation is a Python-based ollvm deobfuscation tool, which now has a perfect performance on ollvm confused C / C + + code compiled on x86 architecture based Linux platform.
OpenArk
OpenArk is an open source anti-rookit(ARK) tool for Windows.
openedr
Open EDR public repository
ossem_modular
OSSEM Modular
rewolf-wow64ext
Helper library for x86 programs that runs under WOW64 layer on x64 versions of Microsoft Windows operating systems.
sysmon-config
Sysmon configuration file template with default high-quality event tracing
sysmon-modular
A repository of sysmon configuration modules
SysmonTools
Utilities for Sysmon
ThreatHunting
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
UPGDSED
Universal PatchGuard and Driver Signature Enforcement Disable
WMIPersistence
WMI Event Subscription Persistence in C#