Use NT Native Registry API to create a registry that normal user can not query.
☆93Dec 7, 2017Updated 8 years ago
Alternatives and similar repositories for HiddenNtRegistry
Users that are interested in HiddenNtRegistry are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆25Jul 24, 2020Updated 6 years ago
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆31Feb 7, 2025Updated last year
- Dll injection through code page id modification in registry. Based on jonas lykk research☆16Jun 18, 2022Updated 4 years ago
- Windows hidden thread suspend POC with code injection☆12May 27, 2017Updated 9 years ago
- This tool will extract the opcodes from the .text section and display in different hex formats for different syntaxes. Works only with va…☆16Feb 9, 2016Updated 10 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Submission, compilation and execution of C# code snippets, using an unmanaged CLR Host☆60Jan 29, 2015Updated 11 years ago
- ☆17Mar 3, 2016Updated 10 years ago
- PowerShell script to bypass UAC using DCCW☆20Jul 29, 2017Updated 8 years ago
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆67Feb 11, 2025Updated last year
- New handle stealing technique for windows apps☆14Oct 6, 2017Updated 8 years ago
- Terms of Use Conditional Access M365 Evilginx Phishlet☆46Jun 23, 2025Updated last year
- A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and …☆337Mar 6, 2025Updated last year
- C++ wrapper for the Windows structured storage implementation known as Compound Files☆20Aug 30, 2020Updated 5 years ago
- A tool similar to netcat, but tunneled over DNS☆18Mar 10, 2017Updated 9 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Cortex EDR Ransomware protection Bypass☆27Feb 8, 2025Updated last year
- Https中间人劫持验证性库☆17Mar 12, 2017Updated 9 years ago
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆50Jan 25, 2025Updated last year
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆107Feb 25, 2025Updated last year
- A Mythic Agent written in PIC C.☆213Feb 4, 2025Updated last year
- RunPE dump - I wrote this to have better control over the analysis of malwares. I can stop and analysis malware when it uses some of the …☆10Jul 1, 2015Updated 11 years ago
- TypeLib persistence technique☆149Oct 22, 2024Updated last year
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆286Sep 18, 2024Updated last year
- Shellcode Loader Utilizing ETW Events☆66Feb 26, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- In-memory hiding technique☆65Jan 5, 2025Updated last year
- Host CLR and run .NET binaries using Rust☆155Dec 23, 2025Updated 7 months ago
- ☆22Jun 24, 2025Updated last year
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆27May 21, 2014Updated 12 years ago
- "Service-less" driver loading☆189Nov 28, 2024Updated last year
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints☆129Jul 11, 2025Updated last year
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆121Oct 20, 2024Updated last year
- GPOAnalyzer is a tool designed to assist in parsing domain Group Policy Object (GPO) files located in the SYSVOL directory.☆28Jun 14, 2024Updated 2 years ago
- Maintain Windows Persistence with an evil Netshell Helper DLL☆12Jul 28, 2018Updated 7 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- .NET assembly loader with patchless AMSI and ETW bypass☆386Apr 19, 2023Updated 3 years ago
- PoC: process watcher patterns to make killing a process hard.☆11Aug 1, 2018Updated 7 years ago
- Execute shellcode via Bluetooth device authentication☆43Feb 19, 2025Updated last year
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆80Dec 23, 2023Updated 2 years ago
- No inline asm,support x86/x64☆65Apr 17, 2021Updated 5 years ago
- A debbuger based dbgeng for WIndows☆34Aug 23, 2017Updated 8 years ago
- A modern Rust implementation of the original Stardust project, providing a sophisticated 32/64-bit shellcode template that features posit…☆66Mar 17, 2025Updated last year