Skip to content
/ Yumekage Public

Demo proof of concept for shadow regions, and implementation of HyperDeceit.

Notifications You must be signed in to change notification settings

Xyrem/Yumekage

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

18 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Yumekage

This repository contains a demo proof of concept implementation for shadowing memory regions in Windows. It was created as part of a blog post discussing the topic and also serves as a basis for the HyperDeceit project which is available at https://github.com/Xyrem/HyperDeceit.

Please do not use this code for production, as it is no where near ready for it. However bug reports and feedback are welcome.

Blog post: https://reversing.info/posts/guardedregions

Media

Demo Windows Demo WinDbg

Credits

  • Everdox for coming up with the idea of abusing context swaps to create hidden memory.

About

Demo proof of concept for shadow regions, and implementation of HyperDeceit.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages