Unsignatured Detours - Runtime Advanced Hooking & Hookless API resolving
-
Updated
Aug 2, 2025 - C
Unsignatured Detours - Runtime Advanced Hooking & Hookless API resolving
A stealthy, header-only C++ library for Windows internals research. Implements disk-based SSN (System Service Number) recovery, manual PE parsing, and page-aligned memory scanning to bypass user-mode EDR/AV hooks.
Bypassing all EDR hooks while maintaining the cleanest callstack of all time with proxy calls and an exception handler.
Add a description, image, and links to the hook-evasion topic page so that developers can more easily learn about it.
To associate your repository with the hook-evasion topic, visit your repo's landing page and select "manage topics."