Skip to content
View picklover's full-sized avatar
🎯
Focusing
🎯
Focusing
  • ZZU
  • ZhengZhou

Block or report picklover

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Just an example of a well-known technique to detect memory tampering via Windows Working Sets.

C 16 6 Updated Jan 15, 2022

VT DEBUGGER

C 57 29 Updated Apr 13, 2023

MemProcFS

C 3,323 413 Updated Jan 19, 2025

This is Qt widget for display binary data in traditional hex editor style

C++ 59 19 Updated Oct 21, 2022

《macOS软件安全与逆向分析》随书的调试器代码

C++ 51 18 Updated Nov 20, 2016

The OpenSource Disassembler

C++ 1,600 142 Updated Oct 27, 2024

base for testing

C++ 162 34 Updated Sep 28, 2024

Manual mapper that uses PTE manipulation, Virtual Address Descriptor (VAD) manipulation, and forceful memory allocation to hide executable pages. (VAD hide / NX bit swapping)

C 307 88 Updated Jan 29, 2022

https://www.codeproject.com/Articles/5348168/Disable-Driver-Signature-Enforcement-with-DSE-Patc

C++ 16 6 Updated Sep 28, 2023

A bunch of JavaScript extensions for WinDbg.

JavaScript 326 47 Updated Nov 28, 2024

Enum and Remove Hook in Windows

Batchfile 36 7 Updated Dec 9, 2024

Windows Object Explorer 64-bit

C 1,684 294 Updated Dec 21, 2024

Intel learning hypervisor and some extend function

C 22 7 Updated Dec 17, 2024

ntoskrnl .data hooks for UM-KM communication

C 36 5 Updated May 26, 2024

Bypassing EasyAntiCheat.sys self-integrity by abusing call hierarchy

C++ 80 24 Updated Oct 6, 2022

从MmPfnData中枚举进程和页目录基址

C++ 153 50 Updated Aug 18, 2023

Mirror of my favourite hacking Zines for the lulz, nostalgy, and reference

Shell 34 27 Updated Feb 18, 2020

AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With …

C 1,095 424 Updated Apr 22, 2021

Detect removed thread from PspCidTable.

C 70 20 Updated Mar 18, 2022

A ProcMon-esque tool for monitoring Windows Kernel Drivers

C++ 54 13 Updated May 31, 2021

A Poc on blocking Procmon from monitoring network events

C++ 100 12 Updated Aug 23, 2022

Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.

C++ 312 66 Updated Mar 26, 2024

open source process monitor

C 261 74 Updated Dec 20, 2023

Process Monitor X v2

C++ 594 123 Updated Jan 22, 2024

Windows Kernel Misc

C 23 16 Updated Sep 3, 2023
C 110 65 Updated Oct 1, 2019

r/w virtual memory without attach

C++ 159 62 Updated Oct 19, 2023

2023年最新整理,qt开发最全面试集锦,含网络,文件系统,数据库,自定义控件,以及视频讲解,文档

325 79 Updated May 20, 2024

Real-time collection of PMCs via ETW

C++ 50 6 Updated Nov 16, 2024
Next