Starred repositories
VMProtect 2.x-3.x x64 Import Deobfuscator
ULTRA FAST Signature Scanner & Generator for IDA Pro 7/8/9+ Compiled with GCC
A 5G Sniffer and Downlink Injector Framework on steroids... And yes, Wireshark supported!!!
A CIA tradecraft technique to asynchronously detect when a process is created using WMI.
A simple way to spoof return addresses using an exception handler
d3d12 wallhack, dx12 wallhack, d3d wallhack, wallhack, d3d12 overlay
Visual Studio Project example for using Microsoft's STL in WDM (Windows Kernel-mode Driver)
KANKOSHEV / CosMapper
Forked from armvirus/CosMapperLoads a signed kernel driver which allows you to map any driver to kernel mode without any traces of the signed / mapped driver.
Minimalistic and foolproof POC for instrumentation callbacks