Commit Graph

  • fe08d3682e Update of the hook 'MmGetSystemRoutineAddress' in order to manage when this function is used with the RtlQueryRegistryValues and RtlQueryRegistryValuesEx to associated both to our new hook of the function 'RtlQueryRegistryValues'. (#16) main Davide NettiandDavide 2025-12-07 17:36:34 +01:00
  • 362f868480 RtlQueryRegistryValues incorrect use finder (#15) Davide NettiandDavide 2025-12-06 14:57:28 +01:00
  • 10cd1edb47 Import symbols fixup also for find_ioctl_handler (#14) Andrea Monzani 2025-11-29 14:31:43 +01:00
  • 51de9f01d4 In the hooks.py file there is an AND instead of the correct OR logical operator. I've fixed it. (#12) Davide Netti 2025-11-12 14:15:28 +01:00
  • 35801ac1c1 Fixed unicode string length calculation in RtlInitUnicodeString (#10) Andrea Monzani 2025-10-25 13:52:17 +02:00
  • 22d9aafc73 Proc exp vuln style (PsLookupProcessByProcessId -> KeStackAttachProcess -> ObCloseHandle) (#8) Davide NettiandDavide 2025-10-06 16:07:58 +02:00
  • ee803ba44a Merge pull request #7 from mnznndr97/main Zeze 2025-09-26 22:39:08 +08:00
  • 5a33536357 Minor fixed Andrea Monzani 2025-09-24 19:03:08 +02:00
  • d8e6e173aa HookObReferenceObjectByHandle now propagates taint for *PsProcessType. Fixes kprocesshacker's arbitrary process termination detection Andrea Monzani 2025-09-24 15:29:03 +02:00
  • 83cfca0449 feat: new logo zeze 2025-03-28 13:05:31 +08:00
  • 15e3aee8e7 Merge pull request #5 from zeze-zeze/ProcessTermination Zeze 2025-03-28 01:22:03 +08:00
  • b25b063d8b fix: tainted_handles operations and vuln title ProcessTermination zeze 2025-03-28 01:19:29 +08:00
  • 1141a57375 edr killer detections R1perXANAX 2025-03-21 18:40:56 +00:00
  • add3e8cb9f fix: specified version for capstone zeze 2025-02-24 23:25:35 +08:00
  • 73e6e32cc2 refactor: remove unused comment in Dockerfile Zeze 2024-01-05 14:03:23 +08:00
  • 3485a60d2f ioctlance zeze 2023-11-09 11:12:15 +08:00