0xTriboulet / T-1
T-1 is a shellcode loader that leverages ML techniques to detect VM environments
☆25Updated 5 months ago
Alternatives and similar repositories for T-1:
Users that are interested in T-1 are comparing it to the libraries listed below
- early cascade injection PoC based on Outflanks blog post, in rust☆57Updated 5 months ago
- Hunting and injecting RWX 'mockingjay' DLLs in pure nim☆59Updated 4 months ago
- Tool designed to simplify the generation of proxy DLLs while addressing common conflicts related to windows.h☆37Updated 6 months ago
- Splitting and executing shellcode across multiple pages☆100Updated last year
- Shellcode Loader Utilizing ETW Events☆63Updated last month
- shell code example☆34Updated last week
- Section-based payload obfuscation technique for x64☆59Updated 8 months ago
- API Hammering with C++20☆46Updated 2 years ago
- A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.☆72Updated last year
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆48Updated 11 months ago
- Windows Thread Pool Injection Havoc Implementation☆28Updated last year
- Shellcode loader using direct syscalls via Hell's Gate and payload encryption.☆89Updated 10 months ago
- Proxy function calls through the thread pool with ease☆25Updated last month
- A collection of position independent coding resources☆76Updated 2 months ago
- Cortex EDR Ransomware protection Bypass☆21Updated 2 months ago
- A modern Rust implementation of the original Stardust project, providing a sophisticated 32/64-bit shellcode template that features posit…☆53Updated last month
- converts sRDI compatible dlls to shellcode☆23Updated 3 months ago
- Demoting PPL anti-malware services to less than a guest user☆60Updated 2 months ago
- ☆54Updated 5 months ago
- ☆29Updated 4 months ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆17Updated 2 years ago
- Rust template/library for implementing your own COFF loader☆50Updated 2 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆24Updated 2 weeks ago
- Sample Rust Hooking Engine☆36Updated last year
- BOF for C2 framework☆41Updated 5 months ago
- A pure C version of SymProcAddress☆26Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 3 years ago
- ☆55Updated 3 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 9 months ago
- 「⚙️」Detect which native Windows API's (NtAPI) are being hooked☆38Updated 4 months ago