H3d9's Stars
tandasat/DdiMon
Monitoring and controlling kernel API calls with stealth hook using EPT
0xnobody/vmpdump
A dynamic VMP dumper and import fixer, powered by VTIL.
AdamOron/PatchGuardBypass
Bypassing PatchGuard on modern x64 systems
tandasat/SimpleSvmHook
SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.
BaumFX/cpp-anti-debug
anti debugging library in c++.
namazso/physmem_drivers
A collection of various vulnerable (mostly physical memory exposing) drivers.
KarisAya/nonebot_plugin_groupmate_waifu
娶群友
zer0condition/ReverseKit
x64 Dynamic Reverse Engineering Toolkit
ZEROWyt/Patchguard-2023
ricab/scope_guard
A modern C++ scope guard that is easy to use but hard to misuse.
kexue-z/nonebot-plugin-setu-now
不可以涩涩
Xyrem/HyperDeceit
HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system tasks with ease.
hasherezade/mal_unpack
Dynamic unpacker based on PE-sieve
lgc-NB2Dev/nonebot-plugin-pjsk
Project Sekai 表情包制作
hasherezade/pe-sieve
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
ldpreload/BlackLotus
BlackLotus UEFI Windows Bootkit
EquiFox/KsDumper
Dumping processes using the power of kernel space !
RF3/VMwareVMX
VMware VMX Crypto Module for Python
JochenKalmbach/StackWalker
Walking the callstack in windows applications
9176324/Shark
Turn off PatchGuard in real time for win7 (7600) ~ later
ChaozhongLiu/DyberPet_GenshinImpact
Genshin Impact Desktop Cyber Pet built with DyberPet
sandboxie-plus/Sandboxie
Sandboxie Plus & Classic
glmcdona/Process-Dump
Windows tool for dumping malware PE files from memory back to disk for analysis.
weak1337/Alcatraz
x64 binary obfuscator
asmjit/asmjit
Low-latency machine code generation
zyantific/zydis
Fast and lightweight x86/x86-64 disassembler and code generation library
BeneficialCode/Game-Cheating-Tutorial
热门网络游戏辅助开发教程
245950258/How-to-create-a-csgo-cheating-program
CSGO游戏透视自瞄辅助实现教程
MiroKaku/ucxxrt
The Universal C++ RunTime library, supporting kernel-mode C++ exception-handler and STL.
hzqst/unicorn_pe
Unicorn PE is an unicorn based instrumentation project designed to emulate code execution for windows PE files.