Updated 2 years ago

VMProtect 3 Static Devirtualization

Updated 2 years ago

VMProtect 3 Virtual Machines Profiler Library

Updated 2 years ago

VMProtect 3 Virtual Machine Handler Emulation

Updated 2 years ago

UnknownField is a tool based clang that obfuscating the order of fields to protect your C/C++ game or code.

Updated 2 years ago

Using ReadDirectoryChangesW to detect CheatEngine

Updated 2 years ago

POC about how to detect windows kernel debug by pool tag.

Updated 2 years ago

Load your driver like win32k.sys

Updated 2 years ago

A poc that abuses Enclave

Updated 2 years ago

POC about how to prevent windbg break

Updated 2 years ago

tysm xeroxz

Updated 1 year ago

Does not work on latest vmp3 because of the new but fairly primitive vmenter obfuscation

Updated 1 year ago

SoulExtraction is a windows driver library for extracting cert information in windows drivers

Updated 1 year ago

Expanding Kernel Lazy Importer

Updated 1 year ago

A simple ida python script to find .data ptr

Updated 11 months ago

VMProtect 3 Static Devirtualization

Updated 2 years ago

VMProtect 3 Virtual Machine Handler Emulation

Updated 2 years ago

VMProtect 3 Virtual Machines Profiler Library

Updated 2 years ago

elevate arbitrary MSR writes to kernel execution

Updated 2 years ago

PSKP - Process-Context Specific Kernel Patches

Updated 2 years ago