0xPrimo / Ntdll-UnhookingLinks
Ntdll Unhooking
☆13Updated 3 months ago
Alternatives and similar repositories for Ntdll-Unhooking
Users that are interested in Ntdll-Unhooking are comparing it to the libraries listed below
Sorting:
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆64Updated 2 years ago
- A basic C2 framework written in C☆60Updated last year
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆54Updated last year
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆48Updated last year
- An advanced utility for converting Windows Portable Executable (PE) files to position-independent code (PIC) shellcode. It enables execut…☆57Updated 5 months ago
- Beacon Object File (BOF) Template☆55Updated 8 months ago
- This is a simple project made to evade https://github.com/thefLink/Hunt-Sleeping-Beacons by using a busy wait instead of beacon's built i…☆34Updated 3 years ago
- Beacon Debugger☆40Updated 9 months ago
- In-memory hiding technique☆56Updated 7 months ago
- Windows C++ Implant for Exploration C2☆38Updated 2 months ago
- Sliver agent rewritten in C++☆47Updated 11 months ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆54Updated 2 months ago
- Implementation of Indirect Syscall technique to pop a calc.exe☆105Updated last year
- A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and re…☆26Updated last year
- (EDR) Dll Unhooking = kernel32.dll, kernelbase.dll, ntdll.dll, user32.dll, apphelp.dll, msvcrt.dll.☆38Updated 2 months ago
- Change hash for a signed pe☆16Updated 2 years ago
- 🗡️ A multi-user malleable C2 framework targeting Windows. Written in C++ and Python☆45Updated last year
- find dll base addresses without PEB WALK☆138Updated 3 weeks ago
- x64 version☆37Updated 3 years ago
- An ICMP channel for Beacons, implemented using Cobalt Strike’s External C2 framework.☆95Updated last month
- ☆56Updated 2 years ago
- ☆50Updated 2 years ago
- ☆36Updated 2 years ago
- ☆30Updated 4 months ago
- BypassCredGuard CS BOF☆43Updated 6 months ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆38Updated 2 years ago
- A nice process dumping tool☆82Updated 3 years ago
- ☆49Updated 3 weeks ago
- A (quite) simple steganography algorithm to hide shellcodes within bitmap image.☆21Updated last year
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆17Updated last year