π» Windows 10 Kernel-mode rootkit
β31Sep 3, 2022Updated 3 years ago
Alternatives and similar repositories for WinKit
Users that are interested in WinKit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Released alongside with a talk at REcon 2023, TheRestarter is an interactive command-line tool is designed to interact with the Windows β¦β14Jun 8, 2023Updated 3 years ago
- Classic DLL injection. Download dll from url and inject. Simple C++ implementationβ11Apr 16, 2022Updated 4 years ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraftβ145May 18, 2024Updated 2 years ago
- Process injection via KernelCallbackTableβ13Jan 28, 2022Updated 4 years ago
- A kernel rootkit with remote command and control interface for windowsβ108Jan 22, 2018Updated 8 years ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Exploring in-memory execution of .NETβ140Apr 20, 2022Updated 4 years ago
- Malware persistence via COM DLL hijacking. C++ implementation exampleβ15May 2, 2022Updated 4 years ago
- Dont Call Me Back - Dynamic kernel callback resolver. Scan kernel callbacks in your system in a matter of seconds!β255Jul 9, 2024Updated 2 years ago
- A spiritual .NET equivalent to the Gargoyle memory scanning evasion techniqueβ52Dec 6, 2018Updated 7 years ago
- My personal shellcode loaderβ32Mar 9, 2023Updated 3 years ago
- Simple and sane compression wrapper library.β19Oct 28, 2022Updated 3 years ago
- WTSRMβ216Aug 7, 2022Updated 3 years ago
- Demo to show how write ALPC Client & Server using native Ntdll.dll syscalls.β21Jan 25, 2022Updated 4 years ago
- PoC showing how a potentially malicious script could be hidden, encrypted, into invisible unicode charactersβ15May 26, 2019Updated 7 years ago
- End-to-end encrypted email - Proton Mail β’ AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Crossplatform tool for inject shellcode into .exe and .dll binaries (x86 and x64)β79Dec 22, 2025Updated 6 months ago
- miscellaneous scripts and programsβ288May 13, 2026Updated 2 months ago
- Enumerate various traits from Windows processes as an aid to threat huntingβ201Jan 13, 2022Updated 4 years ago
- Example of async client/server sockets in .NET 5β17Jun 9, 2021Updated 5 years ago
- Trolling Keyloggers by Forcing them to log Specific Text then freezing themβ21Jul 30, 2022Updated 3 years ago
- Executes shellcode from a remote server and aims to evade in-memory scannersβ31Nov 17, 2019Updated 6 years ago
- hook system call that on user modeβ12Jan 27, 2022Updated 4 years ago
- Simple x86 Trampoline Hookβ44Aug 3, 2022Updated 3 years ago
- A simple PoC to invoke an encrypted shellcode by using an hidden callβ115Nov 19, 2022Updated 3 years ago
- GPU virtual machines on DigitalOcean Gradient AI β’ AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscalβ¦β324Aug 2, 2023Updated 2 years ago
- Various ways to execute shellcodeβ512Mar 13, 2024Updated 2 years ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel spaceβ135Jan 2, 2023Updated 3 years ago
- Bypass Malware Time Delaysβ105Sep 23, 2022Updated 3 years ago
- This script is used to unload PsSetCreateProcessNotifyRoutineEx, PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine and PsSetCrβ¦β63Feb 11, 2024Updated 2 years ago
- Append custom data to signed pe file and DONOT DESTROY SIGNED STATUS.β26Mar 13, 2021Updated 5 years ago
- Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic loβ¦β24Jan 23, 2023Updated 3 years ago
- β10Mar 15, 2017Updated 9 years ago
- Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote mβ¦β172Apr 27, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Easy XOR string encryption for NET based binariesβ138Nov 4, 2023Updated 2 years ago
- Malware?β75Oct 26, 2025Updated 8 months ago
- Bypassing kernel patch protection runtimeβ22Feb 19, 2023Updated 3 years ago
- C# loader capable of running stage-1 from remote url, file path as well as file shareβ15Feb 8, 2023Updated 3 years ago
- A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.β12Aug 2, 2021Updated 4 years ago
- A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).β90Nov 23, 2022Updated 3 years ago
- Inject dll to explorer.exe and hide file from process.β22Apr 24, 2021Updated 5 years ago