tricks
Patches DSE by swapping both data ptrs located in SeValidateImageHeader && SeValidateImageData
Proof of concept code for thread pool based process injection in Windows.
Obfuscate specific windows apis with different apis
Different aproaches to detecting EPT hooks
This program remaps its image to prevent the page protection of pages contained in the image from being modified via NtProtectVirtualMemory.
Rendering on external windows via hijacking thread contexts
Kernel-Mode Driver that loads a dll into every new created process that loads kernel32.dll module
Turn off PatchGuard in real time for win7 (7600) ~ later
A project that demonstrates how to screw with CSGO from Kernel Space. (CSGO Kernel Cheat/Hack) All cleaned up, and with updated offsets.
Generic Script To Bypass Some AntiFrida Checks
SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
Windows IME-based DLL injection. Able to inject a DLL without OpenProcess or a process handle being necessary..
usand - convenient and minimal unshare(1)-based sandbox
A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls
PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and prevent access from external processes.
advanced C/C++ antidebugging library for Windows
Perfect DLL Proxying using forwards with absolute paths.
Universal graphical hook for a D3D9-D3D12, OpenGL and Vulkan based games.
Use RTCore64 to map your driver on windows 11.
Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory scanners