fortra/hw-call-stack
Use hardware breakpoints to spoof the call stack for both syscalls and API calls
Repository profile
An interesting way to detect return address spoofing on x64-windows.
Repository updates
Get generated cryotb/RASD development summaries by email, or follow the weekly and monthly RSS feeds.
Sign in to subscribe by email. RSS feeds are public.
Sign in to subscribeTracked growth, recent movement, and commit velocity from stored repository snapshots.
Latest capture 2026-06-24 13:23
1 capture since 2026-06-24
Stars from baseline 0
All tracked data
Frameworks, package managers, ecosystems, and dependency manifests found during catalog scans.
Scanned 2026-06-24 13:23
r5sw.sln
dotnet ecosystem,
0 dependencies
Searchable topics, generated tags, and stack labels that explain where this repository fits.
Agent instructions and tool configuration paths found in the repository tree.
Nearest indexed repositories by embedding similarity.
Use hardware breakpoints to spoof the call stack for both syscalls and API calls
This tool will allow you to spoof the return addresses of your functions as well as system functions.
works with most invokers, spoofs the return address to bypass the anti cheat and allow detected natives to be called.
Research project: make some elaborate anti-cheat to detect: memory editing, debugging, certificates (and spoofing), injected modules, etc
Stack spoofing Detection for CET processes by comparing shadow and user stacks.
No description.