ExpLife0011

Elite
@ExpLife0011

awesome-windows-kernel-security-development. windows kernel security development

2.1k

IDAPython_Note. IDAPython 's note

85

CVE-2019-0803. Win32k Elevation of Privilege Poc

82

Sagaan-AntiCheat-V2.0. Anti Cheat i made in my free time. Credits to everyone who helped are in the files and some are in the code. I will definitely improve this Anti Cheat along the way, now its just beta. Enjoy.

58

anti-anti-vm-detection-dll-1. C++

30

snifferview. C

26

KeUserModeCallBack. A Simple Example

23

WinFaults. A small header file mapping status codes passed to KiExceptionDispatch before KiPreprocessFault to individual CPU faults.

13

KernelModeMonitor. Kernel-Mode driver and User-Mode application communication project

12

vdebug. C

11

RegEditX. Enhanced Registry Editor

9

AimKit-Pasted-Driver. The BlackBone paste that GreenTea denies he pasted

9

NtCompareSigningLevel-hook. swap the function pointer in NtCompareSigningLevels for undetected driver communication.

9

MoaRpm. The Mother-of-All ReadProcessMemory Classes

8

SAC-Sagaan-AntiCheat-SignatureScanner-. This is a usermode program which just scans signatures of any loaded modules in csgo. This does require you to get signatures of cheats for your game and so on

8

SAC-Sagaan-AntiCheat-OverlayDetector-. This is a usermode program which basically scans windows to check if they are overlay. The program will scan for WS_VISIBLE, WS_EX_LAYERED, WS_EX_TRANSPARENT and any overlay which takes up >90% of the screen. Enjoy!

8

sfilter-1. 内核过滤器

8

portable-executable-resource-editor. Open source interfaces of WinAPI (BeginUpdateResource, UpdateResource, EndUpdateResource) for PE32 & PE32+ files.

8

-RpcViewEx. C++

6

TaskSchedLPE. Task Scheduler LPE by SandboxEscaper

6

smbdoor. kernel backdoor via registering a malicious SMB handler

6

kernel_window_hide. 内核级别隐藏指定窗口

6

SAC-Sagaan-AntiCheat-Module-. This will be injected into your game, or just loaded up on start up. This checks for any extra modules which are loaded into the game

6

reflective-rewrite. Attempt to rewrite StephenFewers Reflective DLL Injection to make it a little more stealthy. Some code taken from Meterpreter & sRDI. Currently a work in progress.

5

HideDriver. Hide Driver,win7*64

5

Awesome-Windows-Exploitation-Study-References. List of Awesome Windows Exploitation Study References

5

gamesense-GUI. indigo hack base.

5

DeleteFileByCreateIrp. 通过创建Irp删除文件,代码抄袭自某杀毒软件*86部分,因此可以看到IDA痕迹

4

MemoryError. WorkInProgress

4

SyscallHook. System call hook for Windows 10 20H1

4

spice-usbdk. A Windows filter driver that supports redirection of USB traffic to user-space application, to be used by Spice USB redirection (windows client side).

4

MiniDrv. The empty driver created by vs2017 (single-binary can running from xp to win10)

4

ShellcodeLoader. Small tool to load shellcodes or PEs to analyze them

4

CVE-2022-21882. win32k LPE

4

SAC-Sagaan-AntiCheat-ModuleThread. This version of the anti cheat monitors the threads created and the modules loaded. will be working on this for awhile, stay tune for future updates!

4

iris. WinDbg extension to perform basic detection of common Windows exploit mitigations

3

LpcPoc. C

3

iDefender. iDefender(冰盾 - 终端主动防御系统)

3

QWidgetDemo. Qt编写的一些开源的demo,预计会有100多个,一直持续更新完善,代码简洁易懂注释详细,每个都是独立项目,非常适合初学者,代码随意传播使用,拒绝打赏和捐赠,欢迎留言评论!

3

wslam. WSL Anti-Malware

3

Windows-Hack-Programming.

3

WordEncrypt. Transparent Encryption

3

JDDebug. C++

2

RefleXXion. RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.

2

FuzzingPaper-1. Recent Fuzzing Paper

2

Fuzzing101. An step by step fuzzing tutorial. A GitHub Security Lab initiative

2

InfinityHookPro. InfinityHookPro Win7 -> Win11 latest

2

IDASignMaker. IDA高级技巧 API符号自动识别库 IDASignMaker

2

ShotHv. ShotHv

2

driver_callback_bypass_1909. 研究和移除各种内核回调,在anti anti cheat的路上越走越远

2

FOKS-TROT. minifilter双缓冲透明加解密过滤驱动

2

GameHacking. A Repository with all Things GameHacking.

2

kernel_gdi.

2

EncryptEngine. Transprent Encryption

2

os-tutorial. How to create an OS from scratch

2

CefBrowser. Qt CefBrowser [Windows/Mac OS]

2

docker-tutorial. :watermelon:犬小哈的 《Docker 学习教程》,( A Tutorial to Docker ) 带您玩转 Docker !!!

1

iMonitor. iMonitor(冰镜 - 终端行为分析系统)

1

iMonitorSDK. 系统监控开发套件(sysmon、promon、edr、终端安全、主机安全、零信任、上网行为管理)

1

MMInject. Kernel DLL Injector using NX Bit Swapping and VAD hide for hiding injected DLL

1
60
Apply