0xPrimo / Ntdll-UnhookingLinks
Ntdll Unhooking
☆13Updated 2 months ago
Alternatives and similar repositories for Ntdll-Unhooking
Users that are interested in Ntdll-Unhooking are comparing it to the libraries listed below
Sorting:
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆54Updated last year
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆38Updated 2 years ago
- ☆27Updated 5 months ago
- BypassCredGuard CS BOF☆42Updated 5 months ago
- Beacon Debugger☆40Updated 8 months ago
- A (quite) simple steganography algorithm to hide shellcodes within bitmap image.☆21Updated last year
- ☆36Updated 2 years ago
- (EDR) Dll Unhooking = kernel32.dll, kernelbase.dll, ntdll.dll, user32.dll, apphelp.dll, msvcrt.dll.☆35Updated last month
- ☆30Updated 3 months ago
- Beacon Object File (BOF) Template☆51Updated 7 months ago
- ☆48Updated last week
- This is a simple project made to evade https://github.com/thefLink/Hunt-Sleeping-Beacons by using a busy wait instead of beacon's built i…☆34Updated 3 years ago
- PoC for a Havoc agent/handler setup with all C2 traffic routed through GitHub. No direct connections: all commands and responses are rela…☆36Updated last week
- Sliver agent rewritten in C++☆45Updated 10 months ago
- EmbedExeLnk by x86matthew modified by d4rkiZ☆42Updated 2 years ago
- A simple BOF (Beacon Object File) to search files in the system☆14Updated last year
- A chrome extension that shows the time but steals the cookies in the back for demonstration purposes.☆21Updated 4 months ago
- ☆54Updated last year
- Persistence via Shell Extensions☆62Updated last year
- x64 version☆36Updated 3 years ago
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆47Updated last year
- Using LNK files and user input simulation to start processes under explorer.exe☆25Updated 9 months ago
- ☆23Updated 4 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆60Updated last year
- Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process☆46Updated 2 years ago
- Less sugar (entropy) for your binaries☆28Updated 3 months ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆53Updated 2 months ago
- BYOVD collection☆23Updated last year
- Performs a global AMSI bypass by patching amsi.dll in memory.☆12Updated last month
- Artemis - C++ Hell's Gate Syscall Implementation☆33Updated last year