systematic exploitation of physical read/write to map unsigned code into the kernel.

Updated 1 year ago

reverse engineering of amlegit/xcheats.cc

Updated 1 year ago

A c++ header only library for inline hooking. Supports x86_64, x86, and arm. Small, simple, and easily detected :)

Updated 1 year ago

Eon Computer Programming Language.

Updated 1 year ago

BEDaisy Strings Dumper

Updated 1 year ago

Updated 1 year ago

VMProtect 3 Static Devirtualization

Updated 1 year ago

VMProtect 3 Virtual Machines Profiler Library

Updated 1 year ago

VMProtect 3 Virtual Machine Handler Emulation

Updated 1 year ago

UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.

Updated 1 year ago

DIYSystemMemoryDump is a tool that forces a lock on the type of system memory dump.

Updated 1 year ago

Using ReadDirectoryChangesW to detect CheatEngine

Updated 1 year ago

POC about how to detect windows kernel debug by pool tag.

Updated 11 months ago

Load your driver like win32k.sys

Updated 10 months ago

A poc that abuses Enclave

Updated 9 months ago

POC about how to prevent windbg break

Updated 8 months ago

tysm xeroxz

Updated 6 months ago

Does not work on latest vmp3 because of the new but fairly primitive vmenter obfuscation

Updated 6 months ago

SoulExtraction is a windows driver library for extracting cert information in windows drivers

Updated 4 months ago

Expanding Kernel Lazy Importer

Updated 4 months ago