ntapi
Here are 37 public repositories matching this topic...
[Deprecated, work in progress alternative: https://github.com/M2Team/NanaRun] Series of System Administration Tools
-
Updated
Dec 7, 2022 - C++
Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
-
Updated
May 7, 2025 - C#
Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!
-
Updated
May 9, 2025 - C#
Go shellcode loader that combines multiple evasion techniques
-
Updated
Jun 21, 2023 - Go
Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++, Crystal and Python
-
Updated
Feb 2, 2026 - C#
Bypass Credential Guard by patching WDigest.dll using only NTAPI functions
-
Updated
Apr 8, 2025 - C++
Shellcode loader written in C and Assembly utilizing direct or indirect syscalls to evade UM EDR hooks
-
Updated
Dec 22, 2024 - C
Some random system tools for Windows
-
Updated
Apr 16, 2022 - Pascal
Impersonate Tokens using only NTAPI functions
-
Updated
Apr 4, 2025 - C++
Vulnerable (on purpose) programs to leak NtReadVirtualMemory address for stealthier API resolution (no GetProcAddress, GetModuleHandle or LoadLibrary in the IAT)
-
Updated
Dec 22, 2025 - C++
Remap ntdll.dll using only NTAPI functions with a suspended process
-
Updated
Apr 13, 2025 - C++
Windows API (WinAPI) functions and system calls with categories in JSON format, including arguments (SAL notation) and more.
-
Updated
Jun 11, 2025 - Python
KNSoft.NDK provides native C/C++ definitions and import libraries for Windows NT.
-
Updated
Jun 18, 2026 - C
Codes that could trigger BSOD (Blue Screen of Death) on Windows.
-
Updated
Jan 17, 2025 - C
Improve this page
Add a description, image, and links to the ntapi topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the ntapi topic, visit your repo's landing page and select "manage topics."