fortra/hw-call-stack
Use hardware breakpoints to spoof the call stack for both syscalls and API calls
An interesting way to detect return address spoofing on x64-windows.
Appears on
Quick read
Latest capture 2026-07-29 03:08
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
3 observed captures since 2026-06-24. Charts use measured snapshots only.
Stars from first capture 0
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
Use hardware breakpoints to spoof the call stack for both syscalls and API calls
This tool will allow you to spoof the return addresses of your functions as well as system functions.
works with most invokers, spoofs the return address to bypass the anti cheat and allow detected natives to be called.
Research project: make some elaborate anti-cheat to detect: memory editing, debugging, certificates (and spoofing), injected modules, etc
Stack spoofing Detection for CET processes by comparing shadow and user stacks.
No description.