KNSoft.NDK provides native C/C++ definitions and import libraries for Windows NT and some specifications.
-
Updated
Feb 20, 2025 - C
8000
KNSoft.NDK provides native C/C++ definitions and import libraries for Windows NT and some specifications.
Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!
Codes that could trigger BSOD (Blue Screen of Death) on Windows.
Malleable shellcode loader written in C and Assembly utilizing direct or indirect syscalls for evading EDR hooks
contains code for fakewer, dll sideloading poc / writeup
Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
Bypass Credential Guard by patching WDigest.dll using only NTAPI functions
Windows API (WinAPI) functions and system calls with categories in JSON format, including arguments (SAL notation) and more.
Windows malware development C/C++ snippets.
obfuscate WINAPI/NTAPI calls easily.
Go shellcode loader that combines multiple evasion techniques
A dedicated repository for exploring offensive kernel-mode techniques.
[Deprecated, work in progress alternative: https://github.com/M2Team/NanaRun] Series of System Administration Tools
Some random system tools for Windows
Add a description, image, and links to the ntapi topic page so that developers can more easily learn about it.
To associate your repository with the ntapi topic, visit your repo's landing page and select "manage topics."