0xTriboulet / T-1
T-1 is a shellcode loader that leverages ML techniques to detect VM environments
☆23Updated 4 months ago
Alternatives and similar repositories for T-1:
Users that are interested in T-1 are comparing it to the libraries listed below
- early cascade injection PoC based on Outflanks blog post, in rust☆54Updated 4 months ago
- Section-based payload obfuscation technique for x64☆59Updated 7 months ago
- A collection of position independent coding resources☆67Updated last month
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆42Updated last year
- Windows Thread Pool Injection Havoc Implementation☆28Updated 11 months ago
- API Hammering with C++20☆45Updated 2 years ago
- A pure C version of SymProcAddress☆25Updated 11 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year
- shell code example☆33Updated this week
- stack spoofing☆79Updated 3 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆70Updated last year
- ☆85Updated 6 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 8 months ago
- A process injection technique using only thread context manipulation☆26Updated last year
- A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.☆72Updated last year
- ☆47Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 7 months ago
- Reimplementation of the KExecDD DSE bypass technique.☆46Updated 6 months ago
- ☆53Updated 4 months ago
- Sample Rust Hooking Engine☆36Updated 11 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆14Updated 2 months ago
- ☆52Updated last month
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…