搜索资源列表
KernelExec
- 从RING0级下启动RING3级的应用程序源代码-from RING0 activated RING3-level application program source code
ntifs
- 一个最新最完整的ntifs.h导入库程序,用于开发无驱动的RING0程序。
R3toR0
- 从RING3进入RING0的方法,不需要驱动
ExcpHookMonitor_0.0.4
- ExcpHook is an open source (see license.txt) Exception Monitor for Windows made by Gynvael Coldwind (of Team Vexillium). t uses a ring0 driver to hook KiExceptionDispatch procedure to detect the exceptions, and then shows information about the except
PRMonitor
- Ring0监控程序PRMonitor源代码
RING0.RING0下检测用HOOK SSDT隐藏进程的代码
- RING0下检测用HOOK SSDT隐藏进程的代码,直接build,适用于XP,2000系统。短小实用。,RING0 detect hidden process by HOOK SSDT code directly build, apply to XP, 2000 systems. Short and practical.
RestoreShadow.rar
- Ring0下恢复SSDT Shadow。,Restore SSDT Shadow.
ring0.zip
- 调用门-无驱进入ring0级最简单的方式,Call gate- hassel into the most simple way ring0 class
RING0
- 无驱动R3进R0,VC源码 无驱动R3进R0,VC源码-No driver R3 into R0, VC source into the non-drive R3 R0, VC source
ring0
- 简单代码打造无敌内存清零和过NP的内存读写-Simple code to create invincible memory cleared and the memory read and write over NP
ring0
- Ring0钩子防网页挂马的一个代码,不错。-Anti-hook Ring0 pages linked to the horse a code, yes.
RegDriver
- Ring0级操作注册表!在驱动开发中,经常会用到对注册表的操作,与Win32的API不同,DDK提供另外一套对注册表操作的相关函数,本代码给出了内核模式下对注册表的所有操作实例!-Ring0 registry class operation! At driver development, often used for the operation of the registry with Win32' s API different, DDK provide another set of r
ring0
- ring0 hook from an Chinese website
InlineReHOOK
- ring0下恢复inline hook 还有点bug-inline hook resume ring0
Ring0RestoreSSDTShadow
- Ring0下恢复SSDT Shadow,是一个完整的VC工程,可以学习学习。-Ring0 resume SSDT Shadow
delphi_PspTerminateProcess
- delphi版内核调用PspTerminateProcess杀进程源码,在ring3下搜索PspTerminateProcess地址,传给ring0,然后在ring0下调用。-delphi kernel call PspTerminateProcess kill the process, source code, in the next ring3 search PspTerminateProcess address, passed ring0, and then ring0 invoked.
RING0INLINEHOOK
- RING0下的恢复所有模块导出函数的INLINE HOOK驱动-RING0 restore all modules under the derived functions INLINE HOOK-driven
Kill360ring0
- RING0下关闭360 需要加载驱动 可以学习学习-RING0 shut down 360 to load the driver can learn to learn
Ring0
- Hook NtQueryDirectoryFile隐藏文件 仅限32位系统-Hook NtQueryDirectoryFile hidden files is limited to 32-bit systems
RING0
- 强删文件RING0代码,驱动强制删除文件-Delete files RING0 code, driving force to delete files