/Detect-hook-buster

A compact tool for detecting AV/EDR hooks in default libaries.

Primary LanguageCMIT LicenseMIT

hook-buster

MIT License Windows 10

Introduction

A compact tool for detecting AV/EDR hooks in default libaries such as ntdll.dll, kernel32.dll and kernelbase.dll.

Example usage:

Usage example