0xTriboulet / T-1Links
T-1 is a shellcode loader that leverages ML techniques to detect VM environments
☆25Updated 7 months ago
Alternatives and similar repositories for T-1
Users that are interested in T-1 are comparing it to the libraries listed below
Sorting:
- early cascade injection PoC based on Outflanks blog post, in rust☆59Updated 7 months ago
- Shellcode Loader Utilizing ETW Events☆63Updated 4 months ago
- Tool designed to simplify the generation of proxy DLLs while addressing common conflicts related to windows.h☆38Updated 8 months ago
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆30Updated 4 months ago
- Section-based payload obfuscation technique for x64☆61Updated 10 months ago
- Hunting and injecting RWX 'mockingjay' DLLs in pure nim☆59Updated 6 months ago
- Proxy function calls through the thread pool with ease☆28Updated 4 months ago
- ☆55Updated 8 months ago
- Sample Rust Hooking Engine☆36Updated last year
- A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.☆72Updated last year
- BYOVD Technique Example using viragt64 driver☆40Updated 11 months ago
- ☆86Updated 10 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆25Updated 2 months ago
- ☆31Updated 2 months ago
- A modern Rust implementation of the original Stardust project, providing a sophisticated 32/64-bit shellcode template that features posit…☆57Updated 3 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated 2 years ago
- A Python script for creating `.lnk` (shortcut) files with embedded encoded data and packaging them into ZIP archives.☆50Updated 5 months ago
- Cortex EDR Ransomware protection Bypass☆24Updated 4 months ago
- BOF for C2 framework☆41Updated 7 months ago
- Splitting and executing shellcode across multiple pages☆103Updated 2 years ago
- A collection of position independent coding resources☆79Updated 4 months ago
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆82Updated 4 months ago
- API Hammering with C++20☆46Updated 2 years ago
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆61Updated last year
- A powerful Windows UI monitoring and DNS exfiltration tool written in Rust, combining advanced UI event capture capabilities with secure …☆16Updated 3 months ago
- A pure C version of SymProcAddress☆27Updated last year
- Callstack spoofing using a VEH because VEH all the things.☆21Updated 3 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆50Updated last year
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated 10 months ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆17Updated 3 years ago