Proof-of-Concept code snippets for a variety of different process injection techniques
☆23Feb 2, 2023Updated 3 years ago
Alternatives and similar repositories for ProcessInjectionPOCs
Users that are interested in ProcessInjectionPOCs are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- BOF to terminate a process via PID as argument☆27Sep 7, 2025Updated last year
- Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2☆13Jul 15, 2023Updated 3 years ago
- ☆14Aug 3, 2026Updated 2 months ago
- It's what all the kids are talking about☆12Apr 25, 2023Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Better version of SharpPick☆14Aug 29, 2025Updated last year
- Command line & PPID spoofing☆31Apr 15, 2023Updated 3 years ago
- A logging ASKPASS binary☆29May 29, 2020Updated 6 years ago
- Havoc plugin allowing in-memory execution of PowerShell cmdlets☆14Dec 14, 2023Updated 2 years ago
- A nim port of C5pider's Ekko project.☆18Oct 1, 2022Updated 4 years ago
- Standalone Go implementation of Metasploit's "db_nmap" and "db_import" commands.☆20Nov 6, 2024Updated last year
- Extracts TEXT section of a PE, ELF, or Mach-O executable to shellcode☆107May 5, 2023Updated 3 years ago
- Matryoshka loader is a tool that red team operators can leverage to generate shellcode for Microsoft Office document phishing payloads.☆44May 24, 2021Updated 5 years ago
- ☆11Aug 10, 2021Updated 5 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A small example of loading BOFs in Python with pure reflection☆19Jan 26, 2023Updated 3 years ago
- ☆14Sep 29, 2025Updated last year
- A Rust crate for parsing Windows user minidumps.☆43May 13, 2026Updated 4 months ago
- Active Directory Enumeration and Exploitation☆12Jul 15, 2026Updated 2 months ago
- Vulnerable (on purpose) programs to leak NtReadVirtualMemory address for stealthier API resolution (no GetProcAddress, GetModuleHandle or…☆42Dec 22, 2025Updated 9 months ago
- ☆14Dec 5, 2024Updated last year
- Little java tool to decrypt passwords from Openfire embedded-db☆16Nov 14, 2015Updated 10 years ago
- Caddy v2 module to filter requests based on C2 profiles☆46Apr 24, 2025Updated last year
- Remove API hooks from a Beacon process.☆77Mar 13, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆117Jan 20, 2025Updated last year
- A Lua module made to solve for the roots of quadratic, cubic and quartic functions.☆12Nov 12, 2019Updated 6 years ago
- Small utility package for manipulating Windows process tokens☆24Apr 26, 2022Updated 4 years ago
- A PoC .NET-specific process injection tool☆59Mar 17, 2024Updated 2 years ago
- The code I write in my blog☆123Updated this week
- Shikata ga nai (仕方がない) encoder ported into go with several improvements☆32Aug 27, 2026Updated last month
- ☆39Aug 6, 2025Updated last year
- Resolve WinAPI func. Custom GetProcAddress and GetModuleHandle written in Nim☆33Jun 2, 2021Updated 5 years ago
- D/Invoke standalone shellcode runners☆38Nov 23, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated last year
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- ☆20Jul 2, 2021Updated 5 years ago
- a port of privkit bof for havoc☆24Dec 8, 2023Updated 2 years ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆23Aug 27, 2022Updated 4 years ago
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated last year
- A C# port of the MinHook API hooking library☆55Oct 5, 2022Updated 4 years ago