Ransomware detection application for Windows using Windows Minifilter driver
-
Updated
Jun 6, 2020 - C++
Ransomware detection application for Windows using Windows Minifilter driver
File system minifilter driver for Windows to block symbolic link attacks.
Easy Transparent Encrypted File System Based on Minifilter File System Driver
Source code for the blog post "Ransomware in the honeypot: how we capture keys with sticky canary files"
Le petit Minifilter Driver surveillant file I/O de processus
A sample Windows minifilter kernel driver that intercepts and filters IRP_MJ_CREATE operations to block execution of a specific process or file open.
Add a description, image, and links to the minifilter-driver topic page so that developers can more easily learn about it.
To associate your repository with the minifilter-driver topic, visit your repo's landing page and select "manage topics."