0xlane / process_ghosting
ProcessGhosting 技术的 rust 实现版本
☆24Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for process_ghosting
- Process Injection via Component Object Model (COM) IRundown::DoCallback().☆54Updated last year
- bring your own vulnerable driver☆81Updated last year
- Kill Protected Process Light Process (include av)☆54Updated last year
- An implementation of an indirect system call☆116Updated last year
- Load static-compiled PE from remote server.☆58Updated 2 years ago
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆61Updated 2 years ago
- Shellcode implementation of Reflective DLL Injection by Golang. Convert DLLs to position independent shellcode☆58Updated 3 years ago
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protections☆95Updated last year
- Beacon compiled using clang☆59Updated last year
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆55Updated last year
- Implementation of Indirect Syscall technique to pop a calc.exe☆93Updated 9 months ago
- ☆12Updated last year
- CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback☆65Updated 2 years ago
- A basic C2 framework written in C☆58Updated 4 months ago
- 64-bit, position-independent reverse tcp shell, built in Rust for Windows.☆44Updated last month
- Without closing windows defender, to make defender useless by removing its token privileges and lowering the token integrity.☆31Updated 2 years ago
- Windows Defender VDM lua collections☆45Updated 2 years ago
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆100Updated last year
- It stinks☆100Updated 2 years ago
- A small PoC that creates processes in Windows☆172Updated 5 months ago
- Windows API Call Obfuscation☆93Updated last year
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆52Updated this week
- shellcode生成框架☆79Updated 4 months ago
- LdrLoadDll Unhooking☆118Updated 2 years ago
- ☆44Updated 2 years ago
- DLL Hollowing PoC - Remote and Self shellcode injection☆70Updated 3 years ago
- 32 bit process inject shellcode to 32 bit process and 64 bit process☆28Updated last year
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆32Updated last year
- Offensive tools written for practice purposes☆149Updated 2 years ago