🛠️ Enhance your application's stealth by resolving WinAPI calls through PEB walking, keeping your import table clean and hidden from scrutiny.
-
Updated
Feb 6, 2026 - C
🛠️ Enhance your application's stealth by resolving WinAPI calls through PEB walking, keeping your import table clean and hidden from scrutiny.
Spectral DCM pipeline for rs-fMRI effective connectivity and dementia conversion analysis.
Compile-time string encryption and import obfuscation for Windows PE32(+) binaries
Little tool and (header-only lib) to investigate Windows Internals. Shout out to @zodiacon. No pull requests (this is actually a mirrored Mercurial repo).
Imports Reconstructor via indirect syscalls (Scylla rebuilt with SysCaller)
Lightweight PoC enumerating processes and reading remote PEBs for triage and research.
Tiny C header that allows easy hiding of WinAPI imports via PEB
PoC shellcode injector using clean syscalls to bypass user-mode hooks in ntdll.dll
Custom implementations of WinAPI functions GetProcAddress and GetModuleHandle by traversing low level Windows data structures.
POC of a better implementation of GetProcAddress for ntdll using binary search
Energy performance of buildings
Debugger checks in 3 ways
Add a description, image, and links to the peb topic page so that developers can more easily learn about it.
To associate your repository with the peb topic, visit your repo's landing page and select "manage topics."