newhony's Stars
MmMapIoSpace/UCMapper
Unknowncheats Magically Optimized Tidy Mapper using nvaudio
TsudaKageyu/minhook
The Minimalistic x86/x64 API Hooking Library for Windows
alphaSeclab/injection-stuff
PE Injection、DLL Injection、Process Injection、Thread Injection、Code Injection、Shellcode Injection、ELF Injection、Dylib Injection, including 400+Tools and 350+posts
Air14/airhv
Simple Intel VT-x hypervisor
Byte-Tree/GN-DLL-CF-IMGUI
lainswork/dwm-screen-shot
将shellcode注入dwm.exe以进行屏幕截取
cs1ime/KernelDwm
Kernel dwm render
HyperDbg/HyperDbg
State-of-the-art native debugging tools
DelphiTeacher/OrangeUI4Lazarus
dalibo/pgshark
Messing with PostgreSQL network traffic to make some usefull things
AdamOron/PatchGuardBypass
Bypassing PatchGuard on modern x64 systems
btbd/access
Access without a real handle
Rythorndoran/PageTableHook
Oxygen1a1/oxgenPdb
a Windows kernel Pdb parsing and downloading library that running purely in kernel mode without any R3 programs.
Gbps/gbhv
Simple x86-64 VT-x Hypervisor with EPT Hooking
zhuhuibeishadiao/PFHook
Page fault hook use ept (Intel Virtualization Technology)
bb33bb/r3epthook
使用vt进行无痕hook,支持r3
DragonQuestHero/PUBG-PAK-Hacker
use windows kernel deriver hidden file and itself to Bypass BE
IcEy-999/Drv_Hide_And_Camouflage
zhuhuibeishadiao/NewHideDriverEx
Hide Driver By MiProcessLoaderEntry
Sqdwr/HideDriver
之前那份是7600的,每次编译搞得好麻烦。更新一个VS2017可以直接编译的。
nlmayday/niuniu
牛牛棋牌前后端完整代码(nodejs+cocos creator)
x64dbg/x64dbg
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
Dennis1000/verysimplelua
VerySimple.Lua - Lua 5.3 for Delphi
strivexjun/DriverInjectDll
Using Driver Global Injection dll, it can hide DLL modules
haidragon/DriverInjectDll
InjectDll
anhkgg/SuperDllHijack
SuperDllHijack:A general DLL hijack technology, don't need to manually export the same function interface of the DLL, so easy! 一种通用Dll劫持技术,不再需要手工导出Dll的函数接口了
wbenny/injdrv
proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC
alexvogt91/Kernel-dll-injector
Kernel-Mode Driver that loads a dll into every new created process that loads kernel32.dll module
landhb/HideProcess
A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager