Contains the definitions for the Windows Internal UserMode API from ntdll.dll, samlib.dll and winsta.dll.
Go shellcode loader that combines multiple evasion techniques
Debug Child Process Tool (auto attach)
Inline syscalls made for MSVC supporting x64 and WOW64
The history of Windows Internals via symbols.
翻译 - Windows Internals通过符号的历史记录。
Bypass for CS:GO's LoadLibrary injection prevention mechanism, achieved by patching one byte of game memory.
Simple project that demonstrates how an ETW consumer can be created just by using NTDLL
woftool is a proof-of-concept utility for creating WOF-compressed files
翻译 - woftool是用于创建WOF压缩文件的概念验证实用程序
Use ntdll/ntoskrnl to implement Kernel32, Advapi32 and other APIs. It includes user-mode and kernel-mode.
Windows 10 PE image loader (LDR) NTDLL component toolbox
manual mapping injector
A shellcode runner / injector / hollower in Go, for windows
Windows 11 Syscall table. Ready to use in direct syscall. Actively maintained.