Black-Angel-Rootkit VS ZwProcessHollowing

Compare Black-Angel-Rootkit vs ZwProcessHollowing and see what are their differences.

Black-Angel-Rootkit

Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality. (by XaFF-XaFF)

ZwProcessHollowing

ZwProcessHollowing is a x64 process hollowing project which uses direct systemcalls, dll unhooking and RC4 payload decryption (by XaFF-XaFF)
Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
Black-Angel-Rootkit ZwProcessHollowing
2 1
565 75
- -
4.4 1.8
6 months ago about 1 year ago
C++ C++
GNU General Public License v3.0 only -
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

Black-Angel-Rootkit

Posts with mentions or reviews of Black-Angel-Rootkit. We have used some of these posts to build our list of alternatives and similar projects.

ZwProcessHollowing

Posts with mentions or reviews of ZwProcessHollowing. We have used some of these posts to build our list of alternatives and similar projects.

What are some alternatives?

When comparing Black-Angel-Rootkit and ZwProcessHollowing you can also consider the following projects:

inline_syscall - Inline syscalls made easy for windows on clang

Jormungandr - Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

syser - syser debugger x32/x64 ring3 with source level debugging/watch view/struct view

Kernel-Process-Hollowing - Windows x64 kernel mode rootkit process hollowing POC.

Corth - It's like Porth, but in C++. Yep, we're going full circle.

x64dbg - An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

Orca - Orca is an Advanced Malware with multifeatures written in C/C++ , work on all windows versions !