This is your work, valued
awesome-windows-kernel-security-development. windows kernel security development
2.1kIDAPython_Note. IDAPython 's note
85CVE-2019-0803. Win32k Elevation of Privilege Poc
82Sagaan-AntiCheat-V2.0. Anti Cheat i made in my free time. Credits to everyone who helped are in the files and some are in the code. I will definitely improve this Anti Cheat along the way, now its just beta. Enjoy.
58anti-anti-vm-detection-dll-1. C++
30snifferview. C
26KeUserModeCallBack. A Simple Example
23WinFaults. A small header file mapping status codes passed to KiExceptionDispatch before KiPreprocessFault to individual CPU faults.
13KernelModeMonitor. Kernel-Mode driver and User-Mode application communication project
12vdebug. C
11RegEditX. Enhanced Registry Editor
9AimKit-Pasted-Driver. The BlackBone paste that GreenTea denies he pasted
9NtCompareSigningLevel-hook. swap the function pointer in NtCompareSigningLevels for undetected driver communication.
9MoaRpm. The Mother-of-All ReadProcessMemory Classes
8SAC-Sagaan-AntiCheat-SignatureScanner-. This is a usermode program which just scans signatures of any loaded modules in csgo. This does require you to get signatures of cheats for your game and so on
8SAC-Sagaan-AntiCheat-OverlayDetector-. This is a usermode program which basically scans windows to check if they are overlay. The program will scan for WS_VISIBLE, WS_EX_LAYERED, WS_EX_TRANSPARENT and any overlay which takes up >90% of the screen. Enjoy!
8sfilter-1. 内核过滤器
8portable-executable-resource-editor. Open source interfaces of WinAPI (BeginUpdateResource, UpdateResource, EndUpdateResource) for PE32 & PE32+ files.
8-RpcViewEx. C++
6TaskSchedLPE. Task Scheduler LPE by SandboxEscaper
6smbdoor. kernel backdoor via registering a malicious SMB handler
6kernel_window_hide. 内核级别隐藏指定窗口
6SAC-Sagaan-AntiCheat-Module-. This will be injected into your game, or just loaded up on start up. This checks for any extra modules which are loaded into the game
6reflective-rewrite. Attempt to rewrite StephenFewers Reflective DLL Injection to make it a little more stealthy. Some code taken from Meterpreter & sRDI. Currently a work in progress.
5HideDriver. Hide Driver,win7*64
5Awesome-Windows-Exploitation-Study-References. List of Awesome Windows Exploitation Study References
5gamesense-GUI. indigo hack base.
5DeleteFileByCreateIrp. 通过创建Irp删除文件,代码抄袭自某杀毒软件*86部分,因此可以看到IDA痕迹
4MemoryError. WorkInProgress
4SyscallHook. System call hook for Windows 10 20H1
4spice-usbdk. A Windows filter driver that supports redirection of USB traffic to user-space application, to be used by Spice USB redirection (windows client side).
4MiniDrv. The empty driver created by vs2017 (single-binary can running from xp to win10)
4ShellcodeLoader. Small tool to load shellcodes or PEs to analyze them
4CVE-2022-21882. win32k LPE
4SAC-Sagaan-AntiCheat-ModuleThread. This version of the anti cheat monitors the threads created and the modules loaded. will be working on this for awhile, stay tune for future updates!
4iris. WinDbg extension to perform basic detection of common Windows exploit mitigations
3LpcPoc. C
3iDefender. iDefender(冰盾 - 终端主动防御系统)
3QWidgetDemo. Qt编写的一些开源的demo,预计会有100多个,一直持续更新完善,代码简洁易懂注释详细,每个都是独立项目,非常适合初学者,代码随意传播使用,拒绝打赏和捐赠,欢迎留言评论!
3wslam. WSL Anti-Malware
3Windows-Hack-Programming.
3WordEncrypt. Transparent Encryption
3JDDebug. C++
2RefleXXion. RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.
2FuzzingPaper-1. Recent Fuzzing Paper
2Fuzzing101. An step by step fuzzing tutorial. A GitHub Security Lab initiative
2InfinityHookPro. InfinityHookPro Win7 -> Win11 latest
2IDASignMaker. IDA高级技巧 API符号自动识别库 IDASignMaker
2ShotHv. ShotHv
2driver_callback_bypass_1909. 研究和移除各种内核回调,在anti anti cheat的路上越走越远
2FOKS-TROT. minifilter双缓冲透明加解密过滤驱动
2GameHacking. A Repository with all Things GameHacking.
2kernel_gdi.
2EncryptEngine. Transprent Encryption
2os-tutorial. How to create an OS from scratch
2CefBrowser. Qt CefBrowser [Windows/Mac OS]
2docker-tutorial. :watermelon:犬小哈的 《Docker 学习教程》,( A Tutorial to Docker ) 带您玩转 Docker !!!
1iMonitor. iMonitor(冰镜 - 终端行为分析系统)
1iMonitorSDK. 系统监控开发套件(sysmon、promon、edr、终端安全、主机安全、零信任、上网行为管理)
1MMInject. Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL
1