- Resources About Hooking. For All Platforms. Currently 300+ Tools And 600+ Posts.
- Famous Tools
- D3DX-Hook -> (8)Tools (6)Post
- Frida-Hook -> (1)Tools (15)Post
- Windows
- Linux -> (9)Tools (19)Post
- Apple
- Android
- Recent Add
- [1688Star][28d] [C++] jmpews/dobby a lightweight, multi-platform, multi-architecture hook framework.
- [316Star][4m] [ObjC] jmpews/hookzzmodules modules deps on HookZz framework.
- [67Star][30d] [C] luoyanbei/testhookzz iOS逆向:使用HookZz框架hook游戏“我的战争”,进入上帝模式
- [283Star][28d] [C] kubo/plthook Hook function calls by replacing PLT(Procedure Linkage Table) entries.
- [385Star][1m] [C] zeex/subhook Simple hooking library for C/C++ (x86 only, 32/64-bit, no dependencies)
- [917Star][26d] [C++] aslody/whale Hook Framework for Android/IOS/Linux/MacOS
- [203Star][28d] [C++] rebzzel/kiero Universal graphical hook for a D3D9-D3D12, OpenGL and Vulcan based games.
- [59Star][2m] [C++] codereversing/directx9hook Runtime DirectX9 Hooking
- [52Star][11m] [C++] gaypig/directx11-hook-with-discord DirectX11 hook with discord
- [40Star][4m] [C++] rebzzel/universal-d3d11-hook Universal hook for DX11 based games written in C++
- [37Star][4m] [C++] niemand-sec/directx11hook Hooking Game Graphic Engines!
- [11Star][4m] [C++] guided-hacking/gh_d3d11_hook Barebones D3D11 hook.
- [5Star][1y] [C++] nexus-devs/nexus-hook Hooking functionality for DirectX11 applications
- [0Star][3m] [Lua] yungtry/gtasa-d3dhook Directx hook GTA:SA via Cheat Engine
- 2015.12 [codereversing] Runtime DirectX Hooking
- [76Star][2m] [Py] hamz-a/jeb2frida Automated Frida hook generation with JEB
- 2020.04 [wundercontrol] [Android] Hooking void method - Frida
- 2019.11 [securify] Android Frida hooking: disabling FLAG_SECURE
- 2019.10 [securify] Automated Frida hook generation with JEB
- 2019.01 [fuzzysecurity] Application Introspection & Hooking With Frida
- 2017.08 [notsosecure] Instrumenting Native Android Functions using Frida
- [269Star][30d] [C#] misaka-mikoto-tech/monohook hook C# method at runtime without modify dll file (such as UnityEditor.dll)
- [423Star][1y] [C] darthton/hyperbone Minimalistic VT-x hypervisor with hooks
- [512Star][2y] [C++] tandasat/ddimon Monitoring and controlling kernel API calls with stealth hook using EPT
- [512Star][30d] [C] martona/mhook A Windows API hooking library
- 2017.11 [apriorit] Mhook Enhancements: 10x Speed Improvement and Other Fixes
- [646Star][9m] [C++] stevemk14ebr/polyhook x86/x64 C++ Hooking Library
- [515Star][27d] [C++] stevemk14ebr/polyhook_2_0 C++17, x86/x64 Hooking Libary v2.0
- [1079Star][4m] [C++] everdox/infinityhook Hook system calls, context switches, page faults and more.
- [1364Star][28d] [C] tsudakageyu/minhook The Minimalistic x86/x64 API Hooking Library for Windows
- [28Star][2y] [C] sentinel-one/minhook The Minimalistic x86/x64 API Hooking Library for Windows
- [1707Star][1y] [C] easyhook/easyhook The reinvention of Windows API Hooking
- [67Star][27d] [C#] easyhook/easyhook-tutorials Contains the source code for the EasyHook tutorials found at
- [14Star][5m] [C#] ulysseswu/vinjex A simple DLL injection lib using Easyhook, inspired by VInj.
- 2017.11 [BinaryAdventure] EasyHook x64 Notepad API Hook part 2
- 2017.11 [BinaryAdventure] API Hooking - Using EasyHook to hook NtCreateFile in Notepad.exe
- [117Star][2y] [C#] tandasat/dotnethooking Sample use cases of the .NET native code hooking technique
- [60Star][2y] [C#] wledfor2/playhooky C# Runtime Hooking Library for .NET/Mono/Unity.
- [34Star][4m] [C#] dangbee/dotnethook A hook proof of concept with no native dependencies. Hook both .NET methods (even framework methods) and Native methods entirely in .NET.
- [31Star][1y] [C#] thaisenpm/loader2 Nova Hook is an open source C# cheat loader currently built for CS:GO
- [16Star][6m] [C#] lontivero/open.winkeyboardhook A simple and easy-to-use .NET managed wrapper for Low Level Keyboard hooking.
- [15Star][2m] [Visual Basic .NET] thaisenpm/loader1 Nova Hook is an open source VB.NET cheat loader currently built for CS:GO
- [11Star][6m] [C#] 20chan/globalhook Simple global keyboard, mouse hook and simulation library written C#
- [NoneStar][C#] elliesaur/dotnethook A hook proof of concept with no native dependencies. Hook both .NET methods (even framework methods) and Native methods entirely in .NET.
- [58Star][3y] [C++] int0/processisolator Utility to hook SSDT of specific process and transfer control to a service (usermode app) for handling to determine action allow/deny API call etc.
- [12Star][5y] [C] s18leoare/hackshield-driver-bypass Bypass HackShield several specific SSDT hook in Ring0
- [8Star][3m] [C] papadp/shd Ssdt Hook Detection tool
- [7Star][11m] [C] cherryzy/process_protect_module Monitor and protect processes use "PsSetCreateProcessNotifyRoutineEx" and kernel ssdt hook.
- [6Star][6y] [C++] wyrover/hkkerneldbg F**k ssdt hook in np, tp, hs
- [3Star][2y] [C] sqdwr/64-bits-inserthook insert a ssdt table to hook
- 2015.12 [insinuator] Investigating Memory Analysis Tools – SSDT Hooking via Pointer Replacement
- 2011.08 [sevagas] Hide files using SSDT hooking
- 2008.11 [talosintelligence] Fun with SSDT Hooks and DEP
- [1866Star][27d] [Py] boppreh/keyboard Hook and simulate global keyboard events on Windows and Linux.
- [787Star][4m] [C++] ysc3839/fontmod Simple hook tool to change Win32 program font.
- [546Star][5m] [C#] crosire/scripthookvdotnet An ASI plugin for Grand Theft Auto V, which allows running scripts written in any .NET language in-game.
- [310Star][29d] [C] gbps/gbhv Simple x86-64 VT-x Hypervisor with EPT Hooking
- [193Star][26d] [C#] justcoding121/windows-user-action-hook A .NET library to subscribe for Windows operating system global user actions such mouse, keyboard, clipboard & print events
- [92Star][3y] [C++] shmuelyr/captainhook CaptainHook is perfect x86/x64 hook environment
- [88Star][2m] [C] tinysec/iathook windows kernelmode and usermode IAT hook
- [79Star][3y] [C] stevemk14ebr/unihook Intercept arbitrary functions at run-time, without knowing their typedefs
- [76Star][24d] [C] danielkrupinski/vac-hooks Hook WinAPI functions used by Valve Anti-Cheat. Log calls and intercept arguments & return values. DLL written in C.
- [45Star][10m] [C#] userr00t/universalunityhooks A framework designed to hook into and modify methods in unity games via dlls
- [44Star][7m] [C++] wopss/renhook An open-source x86 / x86-64 hooking library for Windows.
- [42Star][1m] [Rust] verideth/dll_hook-rs Rust code to show how hooking in rust with a dll works.
- [40Star][1m] [C++] prekageo/winhook
- [38Star][1m] [C++] rolfrolles/wbdeshook DLL-injection based solution to Brecht Wyseur's wbDES challenge (based on SysK's Phrack article)
- [38Star][1m] [Assembly] muffins/rookit_playground Educational repository for learning about rootkits and Windows Kernel Hooks.
- [35Star][2m] [C++] codereversing/wow64syscall WoW64 Syscall Hooking
- [34Star][3y] [C++] menooker/fishhook An inline hook platform for Windows x86/x64
- [34Star][30d] [Py] byzero512/winpwn windows pwntools
- [32Star][2m] [C++] netdex/twinject Automated player and hooking framework for bullet hell games from the Touhou Project
- [30Star][2m] [C] deroko/activationcontexthook hook and force process to load redirected DLL.
- [29Star][4m] [C++] m-r-j-o-h-n/swh-injector An Injector that can inject dll into game process protected by anti cheat using SetWindowsHookEx.
- [27Star][6m] [HTML] flyrabbit/winproject Hook, DLLInject, PE_Tool
- [27Star][3m] [C] tinysec/runwithdll windows create process with a dll load first time via LdrHook
- [24Star][3m] [C] david-reguera-garcia-dreg/phook Full DLL Hooking, phrack 65
- [24Star][5m] [C] maikel233/x-hook-for-csgo Aimtux for Windows.
- [22Star][1m] [Go] castaneai/hinako x86 WinAPI hook written in pure Go
- [22Star][29d] [C++] xbased/xhook Hook Windows API. supports Win7/8/10 x86 and x64 platform.
- [21Star][2m] [C] adrianyy/kernelhook Windows inline hooking tool.
- [21Star][5m] [C] xiaofen9/ssdthook An SSDT hook for Windows
- [19Star][5m] [Java] col-e/simplified-jna Multi-threaded JNA hooks and simplified library access to window/key/mouse functions.
- [18Star][11m] [Assembly] egebalci/hook_api Assembly block for hooking windows API functions.
- [16Star][5m] [C] sin5678/hidedir 使用SSDT HOOK 在windows上隐藏指定文件或者文件夹
- [14Star][3m] [C++] hmihaidavid/hooks A DLL that performs IAT hooking
- [13Star][4y] [C++] jonasblunck/dp Win32 API and COM hooking/tracing.
- [13Star][7m] [C#] kanegovaert/unknown-logger An advanced Windows Keylogger with features like (Disable CMD, Screenshotter, Client Stub Builder, Low Level Keyhooks, Hide Application, Respawner, Delete Chrome and Firefox data, and more!)
- [12Star][8m] [C++] sin5678/wow64hook wow64 syscall filter
- [11Star][6m] [Py] debasishm89/qhook qHooK is very simple python script (dependent on pydbg) which hooks user defined Win32 APIs in any process and monitor then while process is running and at last prepare a CSV report with various interesting information which can help reverse engineer to track down / analyse unknown exploit samples / shellcode.
- [11Star][1y] [C++] therena/findthestupidwindow Windows API hooking project to log all the windows / UIs with the exact timestamp when they are opened.
- [11Star][6y] weixu8/registrymonitor Formely KMon, a Windows Kernel Driver designed to prevent malware attacks by monitoring the creation of registry keys in common autorun locations and prompting the user whether they want to allow the creation of the key. More of an experiment into Kernel level SSDT hooks but a fun project nonetheless
- [10Star][7y] [Py] nitram2342/spooky-hook WinAppDbg helper script to catch API calls
- [9Star][6m] [C++] windy32/win32-console-hook-lib A light-weight console hook library for convenient console interactions
- [8Star][6m] [C++] mgostih/snifferih DLL Hooking Packet Sniffer
- [8Star][27d] [C++] ivan-sincek/keylogger Windows OS keylogger with a hook mechanism (i.e. with a keyboard hook procedure).
- [7Star][2y] [Go] nanitefactory/hookwin10calc Reverse engineered Windows 10 Calculator.exe (UWP application) hacker. 한글/漢文을 배운 윈도우 계산기 패치.
- [5Star][2y] [C++] wanttobeno/window_keyandmousehook Window Key And Mouse Hook
- [4Star][10m] [C++] aschrein/apiparse Small project to learn windows dll hooking techniques based on sources of renderdoc and apitrace
- [4Star][2y] [C#] trojaner/rocketplus Adding extra functionality to RocketMod API by using method hooking [Windows x64 only]. Also provides an API for .NET Method detouring
- [0Star][2y] [C] vallejocc/poc-find-chrome-ktlsprotocolmethod Proof of Concept code to download chrome.dll symbols from chromium symbols store and find the bssl::kTLSProtocolMethod table of pointers (usually hooked by malware)
- 2020.03 [apriorit] How to Hook 64-Bit Code from WOW64 32-Bit Mode
- 2019.10 [sentinelone] How TrickBot Hooking Engine Targets Windows 10 Browsers
- 2019.08 [contextis] Common Language Runtime Hook for Persistence
- 2019.05 [vimeo] DKOM 3.0: Hiding and Hooking with Windows Extension Hosts - Alex Ionescu, Gabrielle Viala, Yarden Shafir - INFILTRATE 2019
- 2019.04 [fsx30] Hooking Heaven’s Gate — a WOW64 hooking technique
- 2018.03 [malwarebytes] Hancitor: fileless attack with a DLL copy trick
- 2017.11 [rootedconmadrid] Pablo San Emeterio - WHF: Windows Hooking Framework [RootedCON 2012 - ESP]
- 2017.07 [huntingmalware] Hooking Windows events without knowing anything about C/C++
- 2017.06 [eyeofrablog] Windows Keylogger Part 2: Defense against user-land
- 2015.06 [codereversing] Syscall Hooking Under WoW64: Implementation (2/2)
- 2015.06 [codereversing] Syscall Hooking Under WoW64: Introduction (1/2)
- 2015.01 [debasish] qHooK - Not Just a Win32 API Hooking Script
- 2014.11 [hypervsir] Using LBR (Last Branch Record) Feature to Detect IDT-Shadowing-Based Malicious IDT Hooking
- 2014.02 [evilsocket] How to Hook Win32 API With Kernel Patching
- 2012.09 [volatility] MoVP 3.1 Detecting Malware Hooks in the Windows GUI Subsystem
- 2011.09 [htbridge] Inline Hooking in Windows
- 2011.08 [mista] Windows Hooks of Death: Kernel Attacks through User-Mode Callbacks
- 2011.08 [htbridge] Userland Hooking in Windows
- 2011.06 [shiftlock] Windows hooks detector
- 2010.09 [redplait] ntdll official hooks
- 2006.01 [sans] KbHook.dll is Not Always Spyware
- [140Star][7m] [C] davidbuchanan314/tardis Trace And Rewrite Delays In Syscalls: Hooking time-related Linux syscalls to warp a process's perspective of time, using ptrace.
- [134Star][1m] [C] poliva/ldpreloadhook a quick open/close/ioctl/read/write/free function hooker
- [94Star][30d] [C] milabs/khook Linux Kernel hooking engine (x86)
- [68Star][1m] [C] ilammy/ftrace-hook Using ftrace for function hooking in Linux kernel
- [45Star][2m] [C] jmpews/evilelf Malicious use of ELF such as .so inject, func hook and so on.
- [35Star][3y] [C] jordan9001/superhide Example of hooking a linux systemcall
- [8Star][2m] [C] rafael-santiago/kook A syscall hooking system for FreeBSD, NetBSD and also Linux.
- [6Star][2y] [C] sizet/lkm_parse_dns_packet linux 核心模組, 使用 netfilter IPv4 hook 監聽和分析 DNS 請求和回應封包.
- [5Star][3m] [C] deb0ch/toorkit A simple useless rootkit for the linux kernel. It is a kernel module which hooks up the open() syscall (or potentially any syscall) to replace it with a custom function.
- 2020.01 [mike] Hooking Linux Libraries for Post-Exploitation Fun
- 2019.12 [jm33] Hook System Calls in Linux 5.x
- 2019.02 [linuxgizmos] Embedded vision cams use MIPI-CSI and USB3 Vision to hook up with Linux dev boards
- 2017.02 [forcepoint] Detecting register-hooking Linux rootkits with Forcepoint Second Look
- 2014.10 [allsoftwaresucks] abusing Mesa by hooking ELFs and ioctl
- 2013.12 [HackersSecurity] DEFCON 18: Function Hooking for Mac OSX and Linux
- 2010.03 [imthezuk] Linux functions hooking using LD_PRELOAD - for fun and profit
- [538Star][2y] [Objective-C++] davidgoldman/inspectivec objc_msgSend hook for debugging/inspection purposes.
- [577Star][1y] [ObjC] rpetrich/captainhook Common hooking/monkey patching headers for Objective-C on Mac OS X and iPhone OS. MIT licensed
- [581Star][5m] [C] yulingtianxia/blockhook Hook Objective-C blocks. A powerful AOP tool.
- [2032Star][3y] [Swift] urinx/iosapphook 专注于非越狱环境下iOS应用逆向研究,从dylib注入,应用重签名到App Hook
- [1122Star][2y] [ObjC] yulingtianxia/fishchat Hook WeChat.app on non-jailbroken devices.
- [129Star][6m] [C] rodionovd/rd_route Function hooking for macOS
- [123Star][4m] [ObjC] smilezxlee/zxhookdetection 【iOS应用安全】hook及越狱的基本防护与检测(动态库注入检测、hook检测与防护、越狱检测、签名校验、IDA反编译分析加密协议示例)
- [68Star][3y] [ObjC] alayshchen/xcodeappplugintemplate App Plugin Project Template For iOS App And Mac App. Make it easy to hook app.
- [66Star][5m] [ObjC] yulingtianxia/blocktracker Tracking block args of Objective-C method based on BlockHook
- [54Star][1m] [Perl] theos/logos Preprocessor that simplifies Objective-C hooking.
- [53Star][4m] [ObjC] smilezxlee/zxhookutil 【iOS逆向】Tweak工具函数集,基于theos、monkeyDev
- 2013.03 [gdssecurity] Retrieving Crypto Keys via iOS Runtime Hooking
- [332Star][4m] [Java] mar-v-in/arthook Library for hooking on ART
- [376Star][4m] [C] turing-technician/fasthook Android ART Hook
- [129Star][4m] [Java] turing-technician/virtualfasthook Android application hooking tool based on FastHook + VirtualApp
- [2236Star][4m] [Java] elderdrivers/edxposed Elder driver Xposed Framework.
- [764Star][25d] [Java] pagalaxylab/yahfa Yet Another Hook Framework for ART
- [128Star][2y] [Java] bmax121/budhook An Android hook framework written like Xposed,based on YAHFA.
- [372Star][29d] [Py] androidhooker/hooker Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to automaticaly intercept and modify any API calls made by a targeted application.
- [571Star][25d] [Java] pagalaxylab/virtualhook Android application hooking tool based on VirtualApp
- [58Star][8m] [Java] nightoftwelve/virtualhookex Android application hooking tool based on VirtualHook/VirtualApp
- [708Star][4m] [Java] ganyao114/sandhook Android ART Hook/Native Inline Hook/Single Instruction Hook - support 4.4 - 10.0 32/64 bit - Xposed API Compat
- [1463Star][1m] [Java] aslody/legend A framework for hook java methods.
- [1741Star][25d] [C] iqiyi/xhook a PLT (Procedure Linkage Table) hook library for Android native ELF
- [429Star][4y] [Makefile] mindmac/androideagleeye An Xposed and adbi based module which is capable of hooking both Java and Native methods targeting Android OS.
- [1990Star][27d] [Java] tiann/epic Dynamic java method AOP hook for Android(continution of Dexposed on ART), Supporting 4.0~10.0
- [1763Star][2y] [Java] ac-pm/inspeckage Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)
- [789Star][2y] [C] ele7enxxh/android-inline-hook thumb16 thumb32 arm32 inlineHook in Android
- [575Star][27d] [Java] aslody/andhook Android dynamic instrumentation framework
- [541Star][4m] [Java] windysha/xpatch This is a tool to repackage apk file, then the apk can load any xposed modules installed in the device. It is another way to hook an app without root device.
- [448Star][5y] [C++] boyliang/allhookinone all method hook approachs for android such as dalvik hook, art hook, elf hook and inline hook
- [401Star][5m] [Java] pqpo/inputmethodholder A keyboard listener for Android which by hooking the InputMethodManager.
- [291Star][1m] [Py] antojoseph/frida-android-hooks Lets you hook Method Calls in Frida ( Android )
- [220Star][2y] [C] gtoad/android_inline_hook Build an so file to automatically do the android_native_hook work. Supports thumb-2/arm32 and ARM64 ! With this, tools like Xposed can do android native hook.
- [216Star][3y] [Java] zhengmin1989/wechatsportcheat 手把手教你当微信运动第一名 – 利用Android Hook进行微信运动作弊
- [195Star][6m] [Java] panhongwei/androidmethodhook android art hook like Sophix
- [190Star][5m] [C++] aslody/elfhook modify PLT to hook api, supported android 5\6.
- [179Star][1m] [Java] 546669204/wechatbot-xposed A WeChat robot unit ,based on the android xposed framework hook to implement WeChat app robot functions
- [148Star][5m] [Java] zhouat/inject-hook for android
- [120Star][4m] [C++] melonwxd/elfhooker 兼容Android 32位和64位。基于EFL文件格式Hook的demo,hook了SurfaceFlinger进程的eglSwapBuffers函数,替换为new_eglSwapBuffers
- [104Star][5y] [Java] rednaga/dexhook DexHook is a xposed module for capturing dynamically loaded dex files.
- [99Star][2y] [Java] piasy/fridaandroidtracer A runnable jar that generate Javascript hook script to hook Android classes.
- [99Star][4m] [C++] woxihuannisja/stormhook StormHook is a Android Hook Framework for Dalvik and Art
- [63Star][28d] [JS] northwavenl/fridax Fridax enables you to read variables and intercept/hook functions in Xamarin/Mono JIT and AOT compiled iOS/Android applications.
- [56Star][1m] [Rust] nccgroup/assethook LD_PRELOAD magic for Android's AssetManager
- [51Star][2m] [Py] hrkfdn/deckard Deckard performs static and dynamic binary analysis on Android APKs to extract Xposed hooks
- [51Star][5y] [C++] ikoz/androidsubstrate_hookingc_examples AndroidSubstrate_hookingC_examples
- [48Star][5m] [C] shunix/androidgothook GOT Hook implemented in Android
- [42Star][29d] [C++] chickenhook/chickenhook A linux / android / MacOS hooking framework
- [34Star][2m] [TS] igio90/frida-onload Frida module to hook module initializations on android
- [25Star][3m] [C++] dodola/dinlinehook simple art inline hook
- [23Star][6m] [C++] legendl3n/smarthooker The smartest hooking library.
- [17Star][29d] [Py] margular/frida-skeleton 本项目旨在帮助安卓测试工程师更方便地hook apk,并且自带证书绑定绕过功能
- [17Star][25d] [C++] vito11/camerahook An prototype to hook android camera preview data of third-party and system apps
- [15Star][2m] [Java] pnfsoftware/jeb2-andhook
- [2Star][4y] [Java] nodoraiz/latchhooks Hack for Android app hooking using latch
- [0Star][4y] serval-snt-uni-lu/hookranker Automatically Locating Malicious Payload in Piggybacked Android Apps (A Hook Ranking Approach)
- [NoneStar][C] gtoad/android_inline_hook_arm64 Build an .so file to automatically do the android_native_hook work. Supports ARM64 ! With this, tools like Xposed can do android native hook.
- [NoneStar][C++] rprop/and64inlinehook Lightweight ARMv8-A(ARM64, AArch64, Little-Endian) Inline Hook Library for Android C/C++
- [NoneStar][Py] fanxs-t/android-ssl_read-write-hook Hook SSL_read and SSL_write functions in the Android application with Frida.
- 2018.11 [bugbountywriteup] Android Hook — ASIS CTF Final 2018 — Gunshops Question Walkthrough
- 2016.03 [sensepost] Android hooking with Introspy
- 2015.12 [d3adend] Android Anti-Hooking Techniques in Java
- 2015.12 [d3adend] Android Anti-Hooking Techniques in Java
- 2015.06 [koz] Substrate - hooking C on Android
- 2015.05 [evilsocket] Android Native API Hooking With Library Injection and ELF Introspection.
- 2015.01 [attify] Xposed Framework for Android Hooking
- 2015.01 [attify] Xposed Framework for Android Hooking
- [277Star][3y] [C++] gellin/teamviewer_permissions_hook_v1 A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.
- [212Star][3y] [C] silvermoonsecurity/passivefuzzframeworkosx This framework is for fuzzing OSX kernel vulnerability based on passive inline hook mechanism in kernel mode.
- [75Star][2y] [C] chinatiny/inlinehooklib 同时支持用户和内核模式的Inlinehook库
- [67Star][5y] [C] malwaretech/basichook x86 Inline hooking engine (using trampolines)
- [15Star][3m] [C] zzy590/basiclibpp A powerful library for inline-hook,lock,compress etc,and it is useful for anti-virus software.
- [14Star][2y] [C] gtoad/android_inline_hook_arm_example
- [10Star][2y] [C] gtoad/android_inline_hook_thumb_example
- [4Star][2y] [C++] wanttobeno/ade32_inlinehook 基于ADE32的inlineHook
- 2018.11 [n0where] Investigate Inline Hooks: PE-sieve
- 2017.12 [userpc] Understanding/Detecting Inline Hooks/ WinAPI Hooks (Ring3)
- 2016.09 [0x00sec] User Mode Rootkits: IAT and Inline Hooking
- 2013.09 [debasish] Inline API Hooking using DLL Injection
- 2012.05 [crowdstrike] ARMv7/Thumb2 Inline Code Hooking
- [18Star][1y] [C] plexsolutions/readhook Red-team tool to hook libc read syscall with a buffer overflow vulnerability.
- [509Star][1m] [C++] 0x09al/rdpthief Extracting Clear Text Passwords from mstsc.exe using API Hooking.
- [315Star][4m] [C] outflanknl/dumpert LSASS memory dumper using direct system calls and API unhooking.
- [304Star][2y] [C] nektra/deviare2 Deviare API Hook
- [136Star][4m] [C] hoshimin/hooklib The functions interception library written on pure C and NativeAPI with UserMode and KernelMode support
- [54Star][5m] [C] passingtheknowledge/ganxo An opensource API hooking framework
- [40Star][3y] [C++] tanninone/usvfs library using api hooking to implement process-local filesystem-independent file links.
- [35Star][4m] [C++] xrivendell/pcsgolh PCSGOLH - Pointless Counter-Strike: Global Offensive Lua Hooks. A open-source Lua API for CS:GO hacking written in modern C++
- [28Star][6m] [JS] shanselman/daskeyboard-q-nightscout Hooking up the DasKeyboard Q REST API to change the key colors in response to diabetic's glucose from NightScout
- [11Star][2m] [Pascal] oranke/proxy-dll-generator PROXY DLL Generator / for very simple API Hooking.
- [9Star][4y] [C++] jonasblunck/dynhook Example library for how to dynamically/statically hook/intercept unmanaged functions and APIs
- [9Star][3m] [C++] hidd3ncod3s/runpedmp RunPE dump - I wrote this to have better control over the analysis of malwares. I can stop and analysis malware when it uses some of the API's i hook and to dump the memory while it is using RunPE/PH techniques.
- [8Star][4m] [C++] nybble04/shady-hook Hooking API calls of a Ransomware
- [4Star][2y] [C++] a7031x/hookapi Handy way to hook x86 or x64 API
- [4Star][29d] [C] microwave89/ntapihook Attempt to Create a Simple and Light-weight Hook Engine Without Use of an LDE
- [NoneStar][C++] vovkos/protolesshooks API monitoring via return-hijacking thunks; works without information about target function prototypes.
- 2020.05 [apriorit] 3 Effective DLL Injection Techniques for Setting API Hooks
- 2019.12 [trendmicro] Waterbear is Back, Uses API Hooking to Evade Security Product Detection
- 2019.11 [hakin9] RdpThief - Extracting Clear Text Passwords from mstsc.exe using API Hooking
- 2019.11 [steve] Equifax is Nowhere Near Off the Hook and CapitalOne Should be Scared.
- 2019.08 [bromium] Agent Tesla: Evading EDR by Removing API Hooks
- 2018.04 [OALabs] Unpacking VB6 Packers With IDA Pro and API Hooks (Re-Upload)
- 2018.01 [OALabs] Analyze JavaScript and VBScript Malware With x64dbg Debugger and API Hooking
- 2017.06 [lallouslab] Introducing Ganxo v0.1 – An open source API hooking framework
- 2017.05 [] Introducing Ganxo v0.1 Alpha – An open source API hooking framework
- 2016.12 [adelmas] API Hooking with IDA Pro
- 2013.01 [volatility] HowTo: Extract "Hidden" API-Hooking BHO DLLs
- 2012.02 [vxsecurity] ApiMapSet Hooking (short guide)
- 2011.02 [codereversing] API Hooking Through Near Call Replacement
- 2008.09 [evilcodecave] Fast ApiSpy (of DeviceIoControl) via oSpy2 Defined Hook
- 2007.02 [trendmicro] GOOGLE AJAX API Hooked
- [128Star][2y] [C] cylancevulnresearch/reflectivedllrefresher Universal Unhooking
- [23Star][6m] [C++] apriorit/simple-antirootkit-sst-unhooker This is a demo project to illustrate the way to verify and restore original SST in case of some malware hooks
- 2017.03 [cylance] Cylance vs. Universal Unhooking Attack
- 2017.02 [cylance] Universal Unhooking: Blinding Security Software
- [302Star][29d] [Py] boppreh/mouse Hook and simulate global mouse events in pure Python
- [220Star][2y] [C++] bromiumlabs/packerattacker C++ application that uses memory and code hooks to detect packers
- [219Star][4m] [C] silight-jp/mactype-patch MacType Patch for DirectWrite Hook
- [202Star][6m] [ObjC] lmsgsendnilself/hookstatistics Logging args based on AOP(Aspectoriented programming)by Method Swizzling
- [175Star][27d] [C] kubo/funchook Hook function calls by inserting jump instructions at runtime
- [151Star][6m] [C] zmrbak/pcwechathook 云课堂《2019 PC微信 探秘》示例代码
- [150Star][28d] [C] vmcall/dxgkrnl_hook C++ graphics kernel subsystem hook
- [144Star][2m] [Py] ethanhs/pyhooked Pure Python hotkey hook, with thanks to pyHook and pyhk
- [141Star][6m] [C++] hasherezade/iat_patcher Persistent IAT hooking application - based on bearparser
- [140Star][30d] [Py] safebreach-labs/pyekaboo Proof-of-concept program that is able to to hijack/hook/proxy Python module(s) thanks to $PYTHONPATH variable
- [139Star][10m] [C#] unknownv2/corehook A library that simplifies intercepting application function calls using managed code and the .NET Core runtime
- [132Star][2y] [C++] m0n0ph1/iat-hooking-revisited Import address table (IAT) hooking is a well documented technique for intercepting calls to imported functions.
- [128Star][9m] [Go] bshuster-repo/logrus-logstash-hook
- [125Star][1m] [C] gdabah/distormx The ultimate hooking library
- [118Star][29d] [JS] skepticfx/hookish Hooks in to interesting functions and helps reverse the web app faster.
- [116Star][2m] [Go] mattbostock/go-ldpreload-backdoor LD_PRELOAD libc hooking using Go
- [114Star][2m] [Ruby] spiderlabs/beef_injection_framework Inject beef hooks into HTTP traffic and track hooked systems from cmdline
- [110Star][2m] [C] hc0d3r/sudohulk 使用ptraceHook系统调用execve, 监控并修改sudo命令的参数
- [109Star][1m] [Py] eset/vba-dynamic-hook dynamically analyzes VBA macros inside Office documents by hooking function calls
- [109Star][4m] [Py] infertux/zeyple Postfix filter/hook to automatically encrypt outgoing emails with PGP/GPG
- [106Star][2m] [Java] pqpo/methodhook hook java methods
- [105Star][1m] [Py] c0demap/codemap a binary analysis tool for "run-trace visualization" provided as IDA plugin.
- [99Star][4y] [C] ionescu007/hookingnirvana Recon 2015 Presentation from Alex Ionescu
- [96Star][8m] [C++] dzzie/vs_libemu Visual Studio 2008 port of the libemu library that includes scdbg.exe, a modification of the sctest project, that includes more hooks, interactive debugging, reporting features, and ability to work with file format exploit shellcode.
- [93Star][2m] [JS] oalabs/frida-wshook Script analysis tool based on Frida.re
- [89Star][2m] [C] xpn/ssh-inject A ptrace POC by hooking SSH to reveal provided passwords
- [88Star][6y] [C] chokepoint/crypthook TCP/UDP symmetric encryption tunnel wrapper
- [88Star][4m] [R] lorenzwalthert/precommit pre-commit hooks for R projects
- [83Star][2m] [Py] enigmabridge/certbot-external-auth Certbot external DNS, HTTP, TLSSNI domain validation plugin with JSON output and scriptable hooks, with Dehydrated compatibility
- [83Star][1m] [C] smealum/udsploit UDS exploit + kernel hooks for 11.3
- [82Star][2m] [JS] pnigos/hookjs javascript function hook
- [79Star][2m] [C++] cseagle/collabreate IDA Pro Collaboration/Synchronization Plugin
- [79Star][29d] [Pascal] delphilite/delphihookutils Delphi Hooking Library by Lsuper
- [77Star][1m] [C] dodola/fbhookfork 从 fb 的 profilo 项目里提取出来的hook 库,自己用
- [76Star][29d] [C++] secrary/hooking-via-instrumentationcallback codes for my blog post:
- [75Star][2y] [C++] hrbust86/hookmsrbysvm hook msr by amd svm
- [73Star][1m] [C] nektra/vtbl-ida-pro-plugin Identifying Virtual Table Functions using VTBL IDA Pro Plugin + Deviare Hooking Engine
- [71Star][30d] [C++] petrgeorgievsky/gtarenderhook GTA SA rendering hook
- [71Star][2m] [C] zyantific/zyan-hook-engine Advanced x86/x86-64 hooking library (WIP).
- [69Star][1y] [Java] bolexliu/apptrack Xposed HookAPP逆向跟踪工具,跟踪Activity与Fragment启动信息等
- [66Star][7y] [C] chokepoint/jynx2 JynxKit2 is an LD_PRELOAD userland rootkit based on the original JynxKit. The backdoor has been replaced with an "accept()" system hook.
- [64Star][5m] [C++] changeofpace/mouhidinputhook MouHidInputHook enables users to filter, modify, and inject mouse input data packets into the input data stream of HID USB mouse devices without modifying the mouse device stacks.
- [63Star][5m] [C++] urshadow/urmem C++11 cross-platform library for working with memory (hooks, patches, pointer's wrapper, signature scanner etc.)
- [60Star][5m] [C] respeak/ts3hook Teamspeak 3 Hook
- [60Star][2m] [Makefile] genuinetools/upmail Email notification hook for
- [60Star][4m] [C#] indieteur/globalhooks Allows you to create global keyboard events
- [59Star][3m] [C] codectile/paradise x86/x86-64 hooking library
- [58Star][2m] [Ruby] jbjonesjr/letsencrypt-manual-hook Allows you to use dehydrated (a Let's Encrypt/Acme Client) and DNS challenge response with a DNS provider that requires manual intervention
- [57Star][1m] [Swift] unixzii/swiftui-hooks A PoC for implementing hooks in SwiftUI
- [55Star][5y] [C++] malwaretech/fsthook A library for intercepting native functions by hooking KiFastSystemCall
- [54Star][2y] [Py] stormshadow07/beef-over-wan Browser Exploitation Framework is a Open-source penetration testing tool that focuses on browser-based vulnerabilities .This Python Script does the changes Required to make hooked Linked Accessible Over WAN .So anyone can use this framework and Attack Over WAN without Port Forwarding [NGROK or any Localhost to Webhost Service Required ]
- [53Star][2y] [C] chen-charles/pedetour modify binary Portable Executable to hook its export functions
- [52Star][4y] [C] zhuhuibeishadiao/pfhook Page fault hook use ept (Intel Virtualization Technology)
- [51Star][4y] breakingmalwareresearch/captain-hook
- [48Star][6m] [Java] greywolf007/mobileq750hook MobileQ750Hook
- [48Star][2m] [C] jay/gethooks GetHooks is a program designed for the passive detection and monitoring of hooks from a limited user account.
- [47Star][27d] [Py] safebreach-labs/backdoros backdorOS is an in-memory OS written in Python 2.7 with a built-in in-memory filesystem, hooks for open() calls and imports, Python REPL etc.
- [45Star][2y] [C++] coltonon/reghookex External mid-function hooking method to retrieve register data
- [44Star][1m] [C] l1nuxdotfun/spacehook minecraft premium undeteck cheat!
- [42Star][1y] [C] dzzie/hookexplorer technical tool to analyze a process trying to find various types of runtime hooks. Interface and output is geared torwards security experts. Average users wont be able to decipher its output.
- [41Star][9y] [C++] cr4sh/ptbypass-poc Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.
- [41Star][5m] [JS] gaoding-inc/runtime-hooks
- [41Star][3m] [Py] killswitch-gui/lterm lterm is a small script built to install a bash hook for full terminal logging.
- [41Star][4m] [C] ntraiseharderror/antihook PoC designed to evade userland-hooking anti-virus.
- [39Star][1m] [C] dodola/traphook
- [38Star][27d] [C++] ganyao114/sandboxhookplugin demo for inject & hook in sandbox
- [36Star][1m] [C] harvie/libpurple-core-answerscripts Most-hackable Pidgin plugin! Framework for hooking scripts to respond received messages for various libpurple clients such as pidgin or finch
- [36Star][2y] [C#] roshly/ayyhook-loader A Free Open Source Cheat Loader
- [35Star][2y] [C++] nickcano/reloadlibrary A quick-and-dirty anti-hook library proof of concept.
- [34Star][6m] [Py] eset/volatility-browserhooks Volatility Framework plugin to detect various types of hooks as performed by banking Trojans
- [33Star][2m] [JS] gr2m/before-after-hook wrap methods with before/after hooks
- [32Star][5m] idkwim/frooksinatra POC of sysenter x64 LSTAR MSR hook
- [32Star][2m] [C++] rokups/hooker Minimalistic hooking library written in C
- [32Star][7m] [ObjC] zjjno/interface-inspector-hook Interface Inspector破解
- [31Star][7m] [C++] ayuto/dynamichooks A C++ library to create function hooks dynamically, so you can easily embed it into other programming languages..
- [31Star][5m] [C++] hoangprod/leospecial-veh-hook Vectored Exception Handling Hooking Class
- [30Star][4y] [C] scorchsecurity/toast User-mode hook bypassing method
- [30Star][1y] [ObjC] nododo/hookdouyin iOS逆向:如何让抖音自动播放下一个视频(懒人癌)
- [29Star][26d] [Kotlin] godtoy/wework-hook-example 企业微信xposed-hook,企业微信Hook,消息收发,自动爆粉
- [29Star][2m] [C] robotn/gohook GoHook, Go global keyboard and mouse hook
- [28Star][3y] [Py] tr3jer/autohookspider 将自动爬虫的结果判断是否属于hooks,并不断抓取url爬啊爬。
- [27Star][1m] [Java] mx-futhark/hook-any-text The goal of this project is to provide an alternative to well established text hookers, whose features are restrained to a certain number of game engines and emulators.
- [27Star][2m] [C++] strobejb/sslhook OpenSSL hooking
- [27Star][1m] [C++] aixxe/cstrike-basehook-linux Internal project base for Counter-Strike: Source on Linux.
- [27Star][30d] [Shell] kintoandar/pre-commit pre-commit hook terraform; pre-commit hook prometheus
- [26Star][3y] [C++] ilyatk/hookengine
- [26Star][3m] [C#] nytrorst/hookme Exported from
- [25Star][3y] [C++] bronzeme/ssdt_hook_x64
- [25Star][2m] [Py] esss/hookman A plugin management system in python to applications (in totally or partially) written in C++.
- [25Star][1m] [Py] rbeuque74/letsencrypt-ovh-hook Let's Encrypt hook for DNS validation for OVH domains
- [24Star][6y] [C] jyang772/hideprocesshookmdl A simple rootkit to hide a process
- [23Star][6m] [Java] jackuhan/loginhook xposed的hook案例
- [22Star][3m] [C#] reloaded-project/reloaded.hooks Advanced native function hooks for x86, x64. Welcome to the next level!
- [21Star][1y] [C#] michel-pi/lowlevelinput.net A thread safe and event driven LowLevelMouse and LowLevelKeyboard Hook
- [21Star][5m] [ObjC] zjjno/cornerstonehook Cornerstone破解
- [20Star][1m] [Py] orndorffgrant/bnhook binary ninja plugin for adding custom hooks to executables
- [20Star][6y] [C] tongzeyu/hooksysenter hook sysenter,重载内核,下硬件断点到debugport,防止debugport清零
- [20Star][4m] [Swift] kealdishx/swiftloadhook Use a hack way to achieve similar functions as Load() or initialize() in OC
- [19Star][29d] [JS] cynops/frida-hooks
- [17Star][2y] [JS] compewter/whoof Web Browser Hooking Framework. Manage, execute and assess web browser vulnerabilities
- [17Star][3y] [C] zhuhuibeishadiao/kernelhooksdetection_x64 x64 Kernel Hooks Detection
- [16Star][3m] [C] osrdrivers/penter penter hook example and driver time recorder
- [15Star][4y] [C++] gfreivasc/vmthook Virtual Method Table Hook
- [14Star][2m] [C] hasherezade/loaderine A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.
- [14Star][5m] [C] manicstreetcoders/appinitglobalhooks-mimikatz Hide Mimikatz From Process Lists
- [14Star][28d] [JS] duolingo/pre-commit-hooks Standardizing our code quality tooling
- [12Star][7m] [C++] mgeeky/prc_xchk User-mode process cross-checking utility intended to detect naive malware hiding itself by hooking IAT/EAT.
- [11Star][7m] [C] david-reguera-garcia-dreg/emuhookdetector hook detector using emulation and comparing static with dynamic outputs
- [11Star][1y] [C++] scorbutics/iathook A library that allows hook any imported function from the IAT (works only in x64)
- [10Star][9m] [ObjC] elegantliar/wechathook iOS非越狱 逆向微信实现防撤回, 修改步数
- [10Star][3m] [C] u2400/libc_hook_demo 一个HIDS agent端的demo
- [9Star][9m] [C++] david-grs/mtrace simple c++ hooks around malloc/realloc/free
- [8Star][10m] coolervoid/bank_mitigations Anti keylogger, anti screen logger... Strategy to protect with hookings or improve your sandbox with spyware detection... - Demo
- [8Star][2m] [C++] cyrex1337/hook.lib easy detour-, vftable-, iat- and eathooking
- [8Star][2m] [C] david-reguera-garcia-dreg/cgaty Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition
- [8Star][3y] [C] hollydi/ring0hook
- [8Star][1y] [Swift] zhangkn/hookingcmethods Hooking & Executing Code with dlopen & dlsym ---Easy mode:hooking C methods
- [7Star][1y] [C++] codereversing/sehveh_hook Hooking functions with structured and vectored exception handling
- [7Star][3y] [Java] fuhuiliu/xposedhooktarget Xposed 插件基础开发之Hook目标
- [7Star][8y] [C++] wyyqyl/hookiat
- [6Star][6y] [C#] aristocat/keyhook A C# library for general hot keys.
- [6Star][5m] [Java] lailune/slrrmultiplayer Street Legal: Redline hook-based Multiplayer modification
- [4Star][3y] [C++] blaquee/apchook hooking KiUserApcDispatcher
- [4Star][2y] [ObjC] corzfree/hookwx 逆向工具
- [4Star][2y] [C++] m0rtale/universal-wndproc-hook Universal WndProc Hook for x86 and x64
- [4Star][1y] [C] nikolait/chess-com-cheat Library that hooks into PR_Write() and PR_Read() in firefox processes and manipulates WebSocket Messages to cheat on chess.com
- [4Star][6y] [C++] simonberson/chromeurlsniffer Hook to Chrome Browser URL and show the current URL on simple textbox
- [3Star][2y] [ObjC] susnmos/xituhook 逆向分析及修复稀土掘金iOS版客户端闪退bug
- [2Star][4m] [Py] swarren/uboot-test-hooks Example "hook" scripts for the U-Boot test framework
- [2Star][2y] [C] synestraa/archultimate.hooklib ArchUltimate hook library
- [2Star][2m] [C] carlomara/qemu-ioctl-hooks Code samples for blog post
- [1Star][1y] [TS] larkintuckerllc/hello-hooks
- [1Star][1y] [C++] smore007/remote-iat-hook Remote IAT hook example. Useful for code injection
- [1Star][2y] [ObjC] wpstarnice/hookstatistics
- [1Star][2y] [C++] zuhhcsg0/nebulahook
- [1Star][2y] [C] chocolateboy/b-hooks-op-annotation A Perl module which allows XS modules to annotate and delegate hooked OPs
- [1Star][5m] [C++] fireboyd78/d3hook The magnificent hooking framework for Driv3r.
- [0Star][1y] [Rust] badboy/travis-after-all-rs The missing
after_all_success
hook for Travis - [0Star][2y] [C] cblack-r7/hashcat-hook A few LD_PRELOAD hooks to fix specific issues with hashcat
- [0Star][2y] [Py] ciscose/sparkhelper A few of functions that help with checking that your bot is being used by an approved organization and for verifying the signature of a web hook request.
- [0Star][2y] [JS] yazeedb/responsive-fdt2-hooks Created with CodeSandbox
- [0Star][10m] zhulmin/iosapphook iOS 逆向开发学习笔记
- [0Star][1y] [shell] keychest/certbot-hooks
- [0Star][5y] [Py] nikseetharaman/grapplinghook Open Source 802.11 Direction Finder
- [NoneStar][C] tandasat/uefivarmonitor The runtime DXE driver monitoring access to the UEFI variables by hooking the runtime service table.
- [NoneStar][C] shoumikhin/elf-hook ELF shared library import table patching for function redirection.
- 2020.02 [zoom] ‘We Were Hooked From Day One’: How Zoom, Zoom Rooms Helped Save the Children Transform Communications
- 2020.02 [cqureacademy] [RSA USA 2020] Explore Adventures in the Underland: Forensic Techniques Against Hackers Evading the Hook
- 2020.01 [WarrantyVoider] RE with WV - Episode #8 Taking over functions with detouring/hooking
- 2019.08 [webroot] Cyber News Rundown: Hookup App Exposes Users
- 2019.07 [0x00sec] Hooking in x64 bits
- 2019.05 [logrocket] How to migrate from HOCs to Hooks
- 2019.05 [codeinsecurity] Using uMod Patcher to create new hooks for Rust (the game)
- 2019.04 [logrocket] Experimental Node.js: testing the new performance hooks
- 2019.04 [malware] 2019-04-03 - QUICK POST: HOOKADS CAMPAIGN RIG EK SENDS AZORULT
- 2019.03 [0x00sec] Defeating Userland Hooks (ft. Bitdefender)
- 2019.03 [illuminati] Why does EpicGamesLauncher hook into every process on my machine? (and keep them open after they close?)
- 2019.02 [malware] 2019-02-28 - FALLOUT EK FROM HOOKADS CAMPAIGN
- 2019.02 [Fig] Hookshotless GTG
- 2019.02 [kaspersky] How pirates hook gamers
- 2019.01 [fsx30] Bypass EDR’s memory protection, introduction to hooking
- 2019.01 [fsx30] Vectored Exception Handling, Hooking Via Forced Exception
- 2019.01 [malware] 2019-01-10 - HOOKADS CAMPAIGN RIG EK PUSHES VIDAR
- 2019.01 [malware] 2019-01-04 - HOOKADS CAMPAIGN RIG EK PUSHES SMOKELOADER
- 2018.11 [traffic] [2018-11-22] HookAds->FalloutEK->KPOT
- 2018.11 [traffic] [2018-11-21] HookAds->FalloutEK->AZORult->NetWireRAT
- 2018.11 [nao] HookAds->FalloutEK pushes Nocturnal Stealer, And new GlobeImposter
- 2018.11 [traffic] [2018-11-10] HookAds->FalloutEK->Vidar->GlobeImposter
- 2018.11 [traffic] [2018-11-08] HookAds->FalloutEK->DanaBot
- 2018.10 [vkremez] Let's Learn: Exploring ZeusVM Banking Malware Hooking Engine
- 2018.10 [traffic] [2018-10-29] HookAds->FalloutEK->AZORult->GlobeImposter+CoalaBot
- 2018.10 [pentest] Offensive IAT Hooking
- 2018.10 [traffic] [2018-10-09] HookAds->FalloutEK->AZORult
- 2018.10 [traffic] [2018-10-06] HookAds->FalloutEK->SmokeLoader->Miner
- 2018.10 [traffic] [2018-10-04] HookAds->FalloutEK->Kraken
- 2018.09 [auth0] Validate User Emails Fast using Kickbox and Auth0 Hooks
- 2018.08 [thedebuggers] Minify HTML in CodeIgniter using Hooks
- 2018.08 [badtrace] Anti-Hooking checks of SmokeLoader 2018
- 2018.07 [BSidesTLV] Deep hooks - Assaf Carlsbad & Yarden Shafir
- 2018.07 [Fig] Suns Grave Keese (Chus+Hook)
- 2018.07 [Fig] Hoverbooots vs Hookshot First (version 2)
- 2018.07 [Fig] Hovers First vs Hookshot First (new vc equip dupe route)
- 2018.05 [pierrchen] Understand Container 6: Hooks and Network
- 2018.05 [apriorit] Detecting Hook and ROP Attacks: Methods with Examples
- 2018.04 [cqureacademy] RSA 2018: Adventures In The Underland: Techniques Against Hackers Evading The Hook
- 2018.03 [traffic] [2018-03-20] HookAds->RigEK->Miner
- 2018.03 [malwarebreakdown] Fobos Campaign Uses HookAds Template and Delivers Bunitu Proxy Trojan via RIG EK
- 2018.03 [sentinelone] Next Post:
- 2018.03 [Fig] Spirit BK Skip: Hookshot Jump vs Superslide
- 2018.03 [malwarebreakdown] HookAds Campaign Is Back And Using RIG EK to Deliver Bunitu Proxy Trojan
- 2018.02 [nytrosecurity] Hooking Chrome’s SSL functions
- 2018.02 [HACKADAY] Brilliant path to stronger wall hooks through 3D printing with reinfocement
- 2017.12 [hasherezade] hook finder vs Process Doppelganging
- 2017.12 [hasherezade] Unpacking Magniber ransomware with PE-sieve (former: 'hook_finder')
- 2017.12 [hshrzd] Hook the planet! Solving FlareOn4 Challenge6 with libPeConv
- 2017.11 [Fig] Hookshotless Chuslide Teleport Explanation
- 2017.11 [Fig] Hovers First vs Hook First in 100%
- 2017.10 [ccsinet] Cybersecurity Trends That Shook 2017
- 2017.09 [nickcano] Hooking LuaJIT
- 2017.09 [arxiv] [1709.08331] By Hook or by Crook: Exposing the Diverse Abuse Tactics of Technical Support Scammers
- 2017.09 [malwarebreakdown] HookAds Campaign Leads to RIG EK and Drops ZeuS Panda.
- 2017.09 [hackersgrid] BeEF – Hooking Browser using Classic 2048 HTML Game
- 2017.08 [hasherezade] hook_finder - a small tool for investigating in-memory patches
- 2017.08 [malwarebreakdown] Malvertising Chain Leads to the HookAds Campaign. RIG Drops Dreambot.
- 2017.07 [malwarebreakdown] Dreambot Dropped by HookAds
- 2017.07 [malwarebreakdown] HookAds Continues to use RIG EK to Drop Dreambot
- 2017.06 [malwarebreakdown] Malvertising Leads to HookAds Campaign Which Redirects to RIG EK at 188.225.74.13. RIG EK Drops Dreambot.
- 2017.06 [malwarebreakdown] HookAds Campaign Leads to RIG EK at 188.225.78.240. RIG EK Drops Dreambot.
- 2017.06 [malwarebreakdown] HookAds Malvertising Campaign Leads to RIG EK at 194.87.93.114 and Drops Dreambot
- 2017.06 [blacksunhackers] Leveraging Application Verifier for Function Hooking and Persistence
- 2017.05 [malwarebreakdown] HookAds Campaign Leads to RIG EK at 188.227.74.169 and 5.200.52.203, Drops Dreambot
- 2017.05 [Fig] Shadow Early with Hookshot Jump Tutorial
- 2017.05 [malwarebreakdown] HookAds Malvertising Campaign Leads to RIG EK at 185.154.53.33, Drops LatentBot
- 2017.05 [csyssec] 使用LRB(最近分支记录)特性检测IDT Hooking
- 2017.04 [MalwareAnalysisForHedgehogs] Malware Analysis - Hook Injection PoC by Robert Kuster
- 2017.04 [Fig] skip bombable wall in dc with hookshot jump [useless]
- 2017.03 [malwarebreakdown] HookAds Campaign Leads to RIG EK at 92.53.104.78
- 2017.02 [malwarebreakdown] HookAds Malvertising Redirects to RIG-v EK at 217.107.219.99. EK Drops Ursnif Variant Dreambot.
- 2017.02 [auth0] Introducing Auth0 Hooks
- 2017.02 [anitian] RSA Conference 2017 – By Hook Or By Crook, We Will
- 2017.02 [cqureacademy] Forensic techniques against hackers evading the hook (notes from NIC conference)
- 2017.01 [engineeringblog] Announcing Docker Hook Support for Pre-Commit
- 2016.11 [malwarebytes] The HookAds malvertising campaign
- 2016.10 [criteo] Criteo to Acquire HookLogic – Strengthening its Performance Marketing Platform
- 2016.08 [securityintelligence] The Increasing Dangers of Code Hooking
- 2016.08 [scorchsecurity] Bypassing user-mode hooks the sneaky way
- 2016.07 [ensilo] Intrusive Applications: 6 Security Issues to Watch Out for in Hooking
- 2016.04 [f] Unprotected WiFi Hook-Ups in action at Collision
- 2016.04 [f] Unprotected WiFi Hook-Ups in action at Collision
- 2016.03 [talosintelligence] Angler Attempts to Slip the Hook
- 2016.01 [beefproject] Hooked Browser Network with BeEF and Google Drive
- 2015.12 [bhconsulting] The ransomware of Christmas present: 60,000 hooked by festive imagery
- 2015.12 [sparkfun] Shapeoko hookup guides and tutorials
- 2015.08 [MalwareTech] Hook Scanner Test (Zeus)
- 2015.08 [malwaretech] User Mode Hook Scanner (Alpha)
- 2015.08 [checkpoint] JavaScript Hooking as a Malicious Website Research Tool | Check Point Software Blog
- 2015.08 [mwrinfosecurity] Dynamic Hooking Techniques: User Mode
- 2015.08 [holisticinfosec] toolsmith: There Is No Privacy - Hook Analyser vs. Hacking Team
- 2015.07 [inopinatus] Hook AWS notifications into Slack with a Lambda function
- 2015.06 [talosintelligence] Hook, Line & Sinker: Catching Unsuspecting Users Off Guard
- 2015.05 [malwarebytes] Scams Within Facebook Press On, Use “Facebook for Business” Hook
- 2015.04 [rtl] Hooking up an Si5351A Voltage Controlled Oscillator to the Local Oscillator Input on an RTL-SDR
- 2015.04 [nabla] Hooking Variadic Functions With Substrate
- 2015.04 [malwaretech] Intercepting all System Calls by Hooking KiFastSystemCall
- 2015.03 [securify] Hooking Swift methods for fun and profit
- 2015.01 [codereversing] Virtual Method Table (VMT) Hooking
- 2014.12 [arduino] How to print a Pirate Hook with your Materia 101
- 2014.11 [siliconblade] Finding Call Reference Hooks in Mac Memory
- 2014.11 [mcafee] Hooking the Mac - Mac OS X Wirelurker malware
- 2014.11 [mcafee] Chinese Trojan Hooks Macs, iPhones
- 2014.10 [quequero] Kaspersky Hooking Engine Analysis
- 2014.09 [christophertruncer] Getting Hooked up with Responder and Beef
- 2014.09 [sparkfun] Electricute - Conductive Velcro-Style Hook and Loop
- 2014.08 [engineeringblog] Announcing pre-commit: Yelp’s Multi-Language Package Manager For Pre-Commit Hooks
- 2014.06 [malwarebytes] Scammers Continue to Hook Users with Free Facebook Hacking
- 2014.06 [malwaretech] Usermode System Call hooking – Betabot Style
- 2014.05 [toolswatch] Hook Analyser v3.1 Released
- 2014.01 [toolswatch] Hook Analyser v3.0 The malware analysis utility released with the support of Cyber Threat Intelligence
- 2014.01 [HackersSecurity] DEFCON 17: Managed Code Rootkits Hooking into Runtime Enviroments
- 2013.12 [publicintelligence] (U//FOUO) New Jersey Fusion Center: School Attacks and Plots Since Sandy Hook
- 2013.12 [incolumitas] IAT hooking
- 2013.11 [publicintelligence] Connecticut State’s Attorney Report on Sandy Hook Elementary School Mass Shooting
- 2013.11 [rsa] Detecting New 50-Troting Shell Hook Malware
- 2013.10 [malwaretech] Ring3 / Ring0 Rootkit Hook Detection 2/2
- 2013.09 [toolswatch] Hook Analyser v2.6 Released
- 2013.09 [malwaretech] Ring3 / Ring0 Rootkit Hook Detection 1/2
- 2013.09 [malwaretech] Fighting Hooks With Hooks – Sandbox Escape
- 2013.07 [siliconblade] Hooking IDT in OS X and Detection
- 2013.07 [siliconblade] Back to Defense: Finding Hooks in OS X with Volatility
- 2013.05 [toolswatch] Hook Analyser v2.5 Released
- 2013.04 [WarrantyVoider] ME3OTH - Hooking Sequence Objects
- 2013.03 [trustwave] Hooked on Packets: Reading PCAPs for D Students - Preview
- 2013.03 [kaspersky] 10 arrests that shook the cybercrime underworld
- 2013.03 [toolswatch] Hook Analyser v2.4 Released
- 2013.02 [freebuf] 恶意软件分析工具—Hook Analyser v2.3
- 2013.02 [toolswatch] Hook Analyser v2.3 Released
- 2013.01 [nengx] QQ2013 聊天记录获取(Hook)
- 2012.12 [rapid7] Introduction to Metasploit Hooks
- 2012.10 [toolswatch] Tools in The Hook – Issue #1 (Ghost in the Wires Review & NetworkMiner Author Interview)
- 2012.10 [forcepoint] Hook, line and sinker: the dangers of Location-Based Services
- 2012.08 [securesolutions] Guide to understanding XSS – Payloads, attack vectors, BeEF hooking, MiTM with Shank and some history
- 2012.08 [zonealarm] Don’t Get Hooked: Anatomy of an Email Scam
- 2012.08 [zonealarm] Don’t Get Hooked: Anatomy of an Email Scam
- 2012.08 [redplait] MsgHookLister
- 2012.06 [redplait] CoRegisterChannelHook in w8 consumer preview
- 2012.03 [rachelbythebay] Hooking up a school to a T1 on the cheap
- 2011.10 [redplait] w8 DelayLoadFailureHookImplementation
- 2011.09 [a1logic] Reversing Stuxnet: 5 (Kernel Hooking)
- 2011.08 [a1logic] Reversing Stuxnet: 3 (Filesystem hooking)
- 2011.03 [redplait] IERT_DelayLoadFailureHook
- 2011.03 [androidcracking] original smalihook java source
- 2010.11 [e] One safe hook handler - E8 Method
- 2010.05 [cleanbytes] A new attack method–Kernel HOok Bypassing Engine ?
- 2010.03 [imthezuk] hooking for fun and profit 2 - logging function calls
- 2009.10 [vexillium] TraceHook v0.0.2
- 2009.10 [vexillium] TraceHook v0.0.2
- 2009.09 [webroot] Roman Polanski Arrest Spawns Headline-Hooking Rogues
- 2009.08 [vexillium] TraceHook v0.0.1 release
- 2009.08 [vexillium] TraceHook v0.0.1 release
- 2009.02 [coldwind] ExcpHook ver 0.0.5-rc2
- 2008.09 [coldwind] Is function hooking in Chrome really a security mechanism?
- 2008.04 [evilcodecave] Hooking the Hook
- 2007.11 [bhconsulting] Spammers use religion as a hook
- 2007.08 [evilcodecave] Something about Firewall hooking and Packet Filtering #2
- 2007.08 [evilcodecave] Something about Firewall hooking and Packet Filtering
- 2006.12 [pediy] Attacks on Themida AntiHook Protection
- 2006.08 [pediy] [已解决]如何用全局Hook记录鼠标滚轮的动作?
- 2005.07 [mckeay] Cisco lets researcher off the hook
- 2004.08 [infosecblog] Long Range Hookup
Contents auto exported by Our System, please raise Issue if you have any question.