0xDeku / NiceKatz
A nice process dumping tool
☆73Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for NiceKatz
- Patch AMSI and ETW in remote process via direct syscall☆77Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- TypeLib persistence technique☆75Updated last month
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆67Updated 9 months ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆164Updated last year
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆113Updated last year
- Do some DLL SideLoading magic☆75Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- ☆108Updated last year
- Create Anti-Copy DRM Malware☆46Updated 3 months ago
- ☆106Updated last year
- A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (…☆165Updated last year
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader☆85Updated 8 months ago
- ☆35Updated last year
- ☆44Updated 2 years ago
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆117Updated 3 months ago
- Malware?☆70Updated last month
- A tool for converting SysWhispers3 syscalls for use with Nim projects☆138Updated 2 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- ☆96Updated last year
- ☆118Updated last year
- Various methods of executing shellcode☆68Updated last year
- ☆59Updated 5 months ago
- SharpElevator is a C# implementation of Elevator for UAC bypass. This UAC bypass was originally discovered by James Forshaw and publishe…☆49Updated 2 years ago
- Beacon Object File allowing creation of Beacons in different sessions.☆76Updated 2 years ago
- A basic C2 framework written in C☆58Updated 4 months ago
- Single stub direct and indirect syscalling with runtime SSN resolving for windows.☆127Updated 2 years ago