Skip to content

A virtualization-based endpoint security solution for Windows

License

Notifications You must be signed in to change notification settings

omerk2511/Sparta

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

46 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Sparta

Sparta is a virtualization-based endpoint security solution for Windows. It's an educational research project of mine, which tries to demonstrate the power of virtualization-based solutions.

Basically, Sparta traces all suspicious kernel mode code executions, kernel structure manipulations, kernel code modifications and sensitive process memory corruptions, in order to detect abnormal behavior which can indicate a malware infection. See the "How It Works?" section for a deeper explanation.

Usage

TBD

Screenshots

Basic Execution (Bootstrapping & CPUID "Spoofing")

basic execution

Invisible Syscall Hooking (TLB Splitting)

shadow hooks

How It Works?

TBD

License

MIT

Authors

About

A virtualization-based endpoint security solution for Windows

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published