0xflux / Rust-Hells-Gate
Rust malware EDR evasion via direct syscalls, fully implemented as an example in Rust
☆30Updated 7 months ago
Alternatives and similar repositories for Rust-Hells-Gate:
Users that are interested in Rust-Hells-Gate are comparing it to the libraries listed below
- early cascade injection PoC based on Outflanks blog post, in rust☆50Updated 2 months ago
- Host CLR and run .NET binaries using Rust☆82Updated this week
- Inject a shellcode in a remote process using Process Hollowing.☆44Updated 3 years ago
- A Rust port of LayeredSyscall — performs indirect syscalls while generating legitimate API call stack frames by abusing VEH.☆132Updated 3 months ago
- A COFF Loader written in Rust☆56Updated this week
- Dirty PoC on how to abuse S1's VEH for Vectored Syscalls and Local Execution☆41Updated 6 months ago
- Reflective DLL self-loading as a library☆19Updated last year
- Command & Control server and agent written in Rust☆34Updated 2 years ago
- a demo module for the kaine agent to execute and inject assembly modules☆38Updated 5 months ago
- ☆46Updated last year
- Rust Implementation of SharpDllProxy for DLL Proxying Technique☆29Updated 2 years ago
- LKM rootkit for modern kernels, with DNS C2 and a simple web interface☆63Updated last week
- Malware?☆69Updated 3 months ago
- Template-based generation of shellcode loaders☆72Updated 9 months ago
- A work in progress BOF/COFF loader in Rust☆46Updated last year
- Rust For Windows Cheatsheet☆115Updated 3 months ago
- T-1 is a shellcode loader that leverages ML techniques to detect VM environments☆23Updated 3 months ago
- Rusty Hell's Gate / Halo's Gate / Tartarus' Gate / FreshyCalls / Syswhispers2 Library☆25Updated 2 years ago
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆42Updated this week
- A 64-bit, position-independent code reverse TCP shell for Windows — built in Rust.☆52Updated 3 weeks ago
- a stage1 DLL loader with sleep obfuscation☆34Updated 2 years ago
- A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.☆72Updated 10 months ago
- 🗡️ A multi-user malleable C2 framework targeting Windows. Written in C++ and Python☆42Updated 10 months ago
- Shellcode loader that executes embedded Lua from Rust.☆82Updated last month
- Tool designed to simplify the generation of proxy DLLs while addressing common conflicts related to windows.h☆35Updated 3 months ago
- Rust implementation of lazy_importer☆45Updated last year
- A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls☆105Updated 4 months ago
- DLL proxying for lazy people☆149Updated last month
- 64-bit, position-independent implant template for Windows in Rust.☆108Updated 3 months ago
- Windows Thread Pool Injection Havoc Implementation☆28Updated 10 months ago