Code Monkey home page Code Monkey logo

jiweihong's Projects

dumpert icon dumpert

LSASS memory dumper using direct system calls and API unhooking.

handlemaster icon handlemaster

Changes handle's access rights using DKOM with a vulnerable driver

herpaderping icon herpaderping

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of a process.

hollowfind icon hollowfind

Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect and divert the forensic analysis techniques. The plugin detects such attacks by finding discrepancy in the VAD and PEB, it also disassembles the address of entry point to detect any redirection attempts and also reports any suspicious memory regions which should help in detecting any injected code.

hollows_hunter icon hollows_hunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

hooklib icon hooklib

The functions interception library written on pure C and NativeAPI with UserMode and KernelMode support

hyperplatform icon hyperplatform

Intel VT-x based hypervisor aiming to provide a thin VM-exit filtering platform on Windows.

infinityhook icon infinityhook

Hook system calls, context switches, page faults and more.

kdu icon kdu

Kernel Driver Utility

malware icon malware

Malware (analysis results, tools, reference, analysis methods, etc.)

md5 icon md5

用C++实现md5加密算法

microsoft-activation-scripts icon microsoft-activation-scripts

A collection of scripts for activating Microsoft products using HWID / KMS38 / Online KMS activation methods with a focus on open-source code, less antivirus detection and user-friendliness.

mimikatz icon mimikatz

A little tool to play with Windows security

minhook icon minhook

The Minimalistic x86/x64 API Hooking Library for Windows

motrix icon motrix

A full-featured download manager.

mouhidinputhook icon mouhidinputhook

MouHidInputHook enables users to filter, modify, and inject mouse input data packets into the input data stream of HID USB mouse devices without modifying the mouse device stacks.

nt_wrapper icon nt_wrapper

A wrapper library around native windows sytem APIs

pe-sieve icon pe-sieve

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.