7h3w4lk3r / RexLdr
Rex Shellcode Loader for AV/EDR evasion
☆31Updated last year
Alternatives and similar repositories for RexLdr
Users that are interested in RexLdr are comparing it to the libraries listed below
Sorting:
- Create Anti-Copy DRM Malware☆56Updated 8 months ago
- ☆36Updated 2 years ago
- Shellcode loader using direct syscalls via Hell's Gate and payload encryption.☆89Updated 11 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆82Updated 6 months ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆28Updated this week
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆35Updated this week
- PowerShell script to generate ShellCode in various formats☆41Updated 7 months ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆84Updated 2 years ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆89Updated last year
- Winsocket for Cobalt Strike.☆98Updated last year
- ☆71Updated last year
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆100Updated 2 years ago
- A modification to fortra's CVE-2023-28252 exploit, compiled to exe☆53Updated last year
- Construct the payload at runtime using an array of offsets☆63Updated 10 months ago
- ☆55Updated 6 months ago
- A 64-bit, position-independent code reverse TCP shell for Windows — built in Rust.☆64Updated 2 weeks ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 7 months ago
- This repo goes with the blog entry at blog.malicious.group entitled "Writing your own RDI / sRDI loader using C and ASM".☆83Updated 2 years ago
- Identify and exploit leaked handles for local privilege escalation.☆107Updated last year
- Explorer Persistence technique : Hijacking cscapi.dll order loading path and writing our malicious dll into C:\Windows\cscapi.dll , when …☆84Updated 2 years ago
- Threadless shellcode injection tool☆64Updated 9 months ago
- Sliver agent rewritten in C++☆44Updated 8 months ago
- NativePayload_PE1/PE2 , Injecting Meterpreter Payload bytes into local Process via Delegation Technique + in-memory with delay Changing R…☆58Updated last year
- ☆123Updated last year
- Reasonably undetected shellcode stager and executer.☆37Updated 8 months ago
- Template-based generation of shellcode loaders☆77Updated last year
- ApexLdr is a DLL Payload Loader written in C☆108Updated 10 months ago
- I have documented all of the AMSI patches that I learned till now☆72Updated last month
- In-memory sleep encryption and heap encryption for Go applications through a shellcode function.☆39Updated last year
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year