搜索资源列表
全局句柄表枚举进程(支持x64)
- 使用ring3与ring0层通信,遍历内核全局句柄表完成进程枚举,有对僵尸进程的判断处理。支持x86,x64。
DeviceControl
- ring3与ring0通信,配合之前的Shadow hook!简单明了-ring3 communicate with ring0, with the previous Shadow hook! Foolproof
xlib
- xlib自用库,常用函数整合。For Ring0/3-xlib For Ring0/3
[7-2]EnumRemoveImageNotify
- 枚举与删除映像回调,映像回调可以拦截RING3 和 RING0的映像加载。- Enumerate and delete image correction, image correction can intercept RING3 and RING0 the image is loaded.
ntring0
- windows,2000xp下采用无驱Ring0-windows, 2000xp adopt hassel Ring0
ring0102
- Check ring0 vulnerability in Windows kernels.Checked:1. SYSENTER2. IO Write Memory3. Bus Write Memory4. Reset CPU in ring05. Zero IDT
ring0103
- 程序直接进RING0读取MBR的IO代码修改版-RING0 read directly into the MBR code modified version of the IO
rtl
- RTL special definitions for ring0 & ring3 in one header.
user
- 用户态与内核态的通信,是windows内核的ring3与ring0 的通信
WinRing
- 通过对本代码中的函数简单调用可以取到系统的Ring0权限。-Through a simple function of the code to the system call can take Ring0 permission.
WinRing100
- 直接进Ring0运行的DELPHI代码.不需要任何特权-Ring0 run directly into the DELPHI code. Does not require any special privileges
ntring0
- windows,2000xp下采用无驱Ring0-windows, 2000xp adopt hassel Ring0
ring0102
- Check ring0 vulnerability in Windows kernels.Checked:1. SYSENTER2. IO Write Memory3. Bus Write Memory4. Reset CPU in ring05. Zero IDT
ring0103
- 程序直接进RING0读取MBR的IO代码修改版-RING0 read directly into the MBR code modified version of the IO
rtl
- RTL special definitions for ring0 & ring3 in one header.
ReloadKernes
- 重载Ring0内核程序可以作为rootkit的学习材料不要用于恶意用途-The overloaded Ring0 kernel can be used as a rootkit learning material not intended for malicious purposes
ring0
- How do I get the privilege of Ring 0 Sometimes it is necessary to access to ports above $FF, such as an IDE controller
sedirected
- Switch ring3 to ring0 从ring3切换到ring0的代码-The Switch ring3 to ring0 Switch ring3 to ring0 code
excedtion_hardware
- Windows2000 XP 从Ring3层进入Ring0层的一种方法,还可以-Windows XP Ring3 layer into Ring0 a kind of method, can also
rinp3_The
- Switch ring3 to ring0 从ring3切换到ring0的代码-The Switch ring3 to ring0 Switch ring3 to ring0 code