Process Cloning

Updated 8 months ago

/proc/kmem reimplementation for windows

Updated 8 months ago

run code in an address space not associated with a process.

Updated 8 months ago

old probe from 6/xx/2020 to test theoretical page table concepts

Updated 8 months ago

inserts a PML4E where a prior PML4E is set to not present, pointing at the PDPT that contains the dll.

Updated 8 months ago

swap driver on disk and memory with a Microsoft driver.

Updated 8 months ago

hook all win32k syscalls with a single .data pointer swap

Updated 8 months ago

Extracts the files embedded inside of a .NET AppHost.

Updated 8 months ago

Updated 8 months ago

force delete any file (and directory)

Updated 8 months ago

elevate arbitrary MSR writes to kernel execution

Updated 8 months ago

Highly Modular Driver Mapper

Updated 8 months ago

Tool to bulk-check username availability on Uplay.

Updated 8 months ago

c++ header only library for usermode utils

Updated 8 months ago

VMProtect 2 Virtual Instruction Assembler

Updated 8 months ago

VMProtect 2 Virtual Machines Profiler Library

Updated 8 months ago

VMProtect 2 CLI Virtual Machine Information Displayer

Updated 8 months ago

VMProtect 2 Virtual Machine Hooking Library

Updated 8 months ago

VMProtect 2 Qt Virtual Instruction Inspector

Updated 8 months ago

VMProtect 2 Usermode Virtual Instruction Hook Demo

Updated 8 months ago