Pinned Repositories
analyzeMFT
antispy
AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its assistance,you can easily spot and neutralize malwares hidden from normal detectors.
bitvisor
A git clone of the official mercurial repository
BLUESPAWN
An Active Defense and EDR software to empower Blue Teams
darwin-xnu
The Darwin Kernel (mirror)
DdiMon
Monitoring and controlling kernel API calls with stealth hook using EPT
Detours
Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
dnslib
Simple C++ library designed for encoding and decoding of DNS protocol packets
etw-providers-docs
Document ETW providers
try2crack's Repositories
try2crack/antispy
AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its assistance,you can easily spot and neutralize malwares hidden from normal detectors.
try2crack/bitvisor
A git clone of the official mercurial repository
try2crack/BLUESPAWN
An Active Defense and EDR software to empower Blue Teams
try2crack/darwin-xnu
The Darwin Kernel (mirror)
try2crack/DdiMon
Monitoring and controlling kernel API calls with stealth hook using EPT
try2crack/Detours
Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
try2crack/dnslib
Simple C++ library designed for encoding and decoding of DNS protocol packets
try2crack/etw-providers-docs
Document ETW providers
try2crack/hollows_hunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
try2crack/HyperPlatform
Intel VT-x based hypervisor aiming to provide a thin VM-exit filtering platform on Windows.
try2crack/injdrv
proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC
try2crack/IPC
IPC is a C++ library that provides inter-process communication using shared memory on Windows. A .NET wrapper is available which allows interaction with C++ as well.
try2crack/Kernel-Bridge
Windows kernel hacking framework, driver template, hypervisor and API written on C++
try2crack/krabsetw
KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
try2crack/KTL
Kernel Template Library: STL-style containers and tools for Windows kernel space programming
try2crack/libpeconv
A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl
try2crack/messageanalyzer-archive
Microsoft Message Analyzer EOL Archive
try2crack/OpenArk
OpenArk is an open source anti-rookit(ARK) tool for Windows.
try2crack/openedr
Open EDR public repository
try2crack/ossem_modular
OSSEM Modular
try2crack/rewolf-wow64ext
Helper library for x86 programs that runs under WOW64 layer on x64 versions of Microsoft Windows operating systems.
try2crack/sec-books-part1
:books: 网安类绝版图书
try2crack/sysmon-config
Sysmon configuration file template with default high-quality event tracing
try2crack/sysmon-modular
A repository of sysmon configuration modules
try2crack/SysmonForLinux
try2crack/SysmonTools
Utilities for Sysmon
try2crack/ThreatHunting
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
try2crack/try2crack.github.io
try2crack/UPGDSED
Universal PatchGuard and Driver Signature Enforcement Disable
try2crack/WMIPersistence
WMI Event Subscription Persistence in C#