Windows Process Protection Library (x64)
Malware (analysis results, tools, reference, analysis methods, etc.)
Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide
Red Teaming Tactics and Techniques
Dynamic detouring support for the DHooks 2 SourceMod extension
Converts PE into a shellcode
Research on Anti-malware and other related security solutions
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
A more stealthy variant of "DLL hollowing"
Various snippets created during malware analysis
Python antivirus evasion tool
Phantom DLL hollowing PoC
My notes while studying Windows internals
Resources About Windows Security. 1100+ Open Source Tools. 3300+ Blog Post and Videos.
windows kernel security development
This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples.