0xlane / ppspoofing
Rust编写的父进程PID欺骗技术测试工具
☆53Updated 2 years ago
Alternatives and similar repositories for ppspoofing:
Users that are interested in ppspoofing are comparing it to the libraries listed below
- DLL 转发工具方法。☆51Updated last year
- 一款基于Http.sys的利用工具 ZhuriLab/Joker 备份☆23Updated 2 years ago
- Without closing windows defender, to make defender useless by removing its token privileges and lowering the token integrity.☆33Updated 2 years ago
- power-kill is a project that kill protected processes (such as EDR or AV) by injecting shellcode into high privilege processes☆46Updated 3 years ago
- works but not work, cao!☆24Updated 3 years ago
- 看起来叫BabyBypass,实际啥都会记一些☆16Updated last year
- HVNC based on RustDesk☆87Updated 9 months ago
- 不依赖驱动的跨平台抓包工具☆33Updated 2 years ago
- RawCopy - Golang implementation☆21Updated 2 years ago
- CobaltStrike Reflective Dll Source☆19Updated 3 years ago
- A SigFlip implement in golang☆46Updated 3 years ago
- Golang implementation of the research by @jonaslyk and the drafted PoC from @LloydLabs☆25Updated 3 years ago
- ReturnGate, just like HellsGate.☆66Updated 2 years ago
- 优化了GetSystemEarlyBird的代码结构☆21Updated 4 years ago
- A packer which adds encrypted shell to protect your PE file☆19Updated 3 months ago
- Evasive loader to bypass static detection☆56Updated last year
- Learning notes of amazing Sliver C2 project.☆25Updated last year
- PPID Spoofing☆16Updated 4 years ago
- improved shellcode template for b1tg/rust-windows-shellcode☆27Updated 3 years ago
- BOF内存运行exe☆26Updated last year
- BOF/COFF obj file to PIC(shellcode). by golang☆37Updated 2 years ago
- ProcessGhosting 技术的 rust 实现版本☆24Updated 3 months ago
- 调用x64dbg中的loadll.exe白加黑示例代码☆60Updated 8 months ago
- ☆16Updated 3 years ago
- 简单安排一下 autochk.sys 这个rootkit☆71Updated last year
- 自用的shellcode生成框架☆30Updated last year
- MSSQL CLR for pentest.☆54Updated last year
- ☆35Updated 6 years ago
- 32 bit process inject shellcode to 32 bit process and 64 bit process☆29Updated last year
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆15Updated last year